Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by the SMAP team in the latest version of the app.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership. | |
| Title | Weak password recovery mechanism for forgotten password in MobiAPParc | |
| First Time appeared |
Mobiapparc
Mobiapparc mobiapparc |
|
| Weaknesses | CWE-640 | |
| CPEs | cpe:2.3:a:mobiapparc:mobiapparc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mobiapparc
Mobiapparc mobiapparc |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-17T18:10:03.923Z
Reserved: 2026-07-06T11:42:50.483Z
Link: CVE-2026-14850
Updated: 2026-09-17T18:09:57.489Z
Status : Received
Published: 2026-09-17T14:17:12.117
Modified: 2026-09-17T19:16:37.523
Link: CVE-2026-14850
No data.
OpenCVE Enrichment
No data.
