CVE-2026-14850 Details
Description
The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.
A vulnerability exists in the password reset functionality of the SMAP MobiAPParc application, which is used for managing parking payments in Palma City. This vulnerability allows unauthorized account modifications by exploiting improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for any user without verifying account ownership. The issue affects MobiAPParc versions 0 through 2.28 on iOS and versions 0 through 2.42 on Android.
The vulnerability has been fixed in the latest version of the MobiAPParc app.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 17, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/weak-password-recovery-mechanism-forgotten-password-mobiapparc | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-640 | Weak Password Recovery Mechanism for Forgotten Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SMAP MobiAPParc | >= 0, <= 2.28 >= 0, <= 2.42 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 17, 2026 | New CVE Received | [email protected] |
Volerion