---
id: CVE-2026-93556
title: >-
  The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter,
  which specifies the account whose password is to be changed
summary: >-
  The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter,
  which specifies the account whose password is to be changed. The JWT token for
  the recovery process is not validated against the user specified in that
  parame…
severity: critical
cvss: 9.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-639
vendor: Kompini
product: Tankuam Places
affected:
  - tankuam_places < 25 November 2025
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:41:38.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93556'
references:
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/direct-references-unsafe-objects-idor-tankuam-places-kompini
    label: cve-coordination@incibe.es
tags:
  - nvd
  - cve.org
epss: 0.00305
epssPercentile: 0.20724
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-22T10:11:47.216044Z'
cvssSource: cna
ingestedAt: '2026-09-22T10:01:43.987Z'
---

## Overview

The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
