CVE-2026-14850
HIGH
8,8
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.
640
Weak Password Recovery Mechanism for Forgotten Password
IncompleteCommon Consequences
Security Scopes Affected:
Access Control
Availability
Integrity
Other
Potential Impacts:
Gain Privileges Or Assume Identity
Dos: Resource Consumption (Other)
Other
Applicable Platforms
All platforms may be affected
https://www.incibe.es/en/incibe-cert/notices/aviso/weak-password-recovery-mecha…