High severityNVD Advisory· Published Sep 17, 2026
CVE-2026-14850
CVE-2026-14850
Description
The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.