CVE-2026-14850
Weak password recovery mechanism for forgotten password in MobiAPParc
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.
| CWE | CWE-640 |
| Vendor | mobiapparc |
| Product | mobiapparc |
| Published | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for mobiapparc mobiapparc
Be the first to know when new unknown vulnerabilities affecting mobiapparc mobiapparc are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
MobiAPParc / MobiAPParc
0 ≤ 2.28 0 ≤ 2.42
References
Credits
Llorenç Romá