CVE-2026-14850

Summary

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.

Affected Software

VendorProductVersion RangeStatus
MobiAPParcMobiAPParc0 <= 2.28affected
MobiAPParcMobiAPParc0 <= 2.42affected

Weaknesses

  • CWE-640: CWE-640 Weak Password Recovery Mechanism for Forgotten Password

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References