{"id":"CVE-2026-14850","published":"2026-09-17T14:17:12.117","lastModified":"2026-09-18T19:21:49.497","description":"The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-640"],"vendors":[],"products":[],"references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/weak-password-recovery-mechanism-forgotten-password-mobiapparc","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}