Weak password recovery mechanism for forgotten password in MobiAPParc

Posted date 17/09/2026
Identificador
INCIBE-2026-640
Importance
4 - High
Affected Resources
  • IOS MobiAPParc v0 – v2.28;
  • Android MobiAPParc v0 – v2.42.
Description

INCIBE has coordinated the disclosure of a high-severity vulnerability affecting SMAP’s MobiAPParc, an app that enables users to pay for parking in regulated parking zones and in municipal car parks managed by Palma City Council. The vulnerability was discovered by Llorenç Romá.

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:

  • CVE-2026-14850: CVSS v4.0: 8.8 | CVSS AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H | CWE-640
Solution

The vulnerability has been fixed by the SMAP team in the latest version of the app.

Detail

CVE-2026-14850: the password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-14850 Alta No SMAP