Weak password recovery mechanism for forgotten password in MobiAPParc
- IOS MobiAPParc v0 – v2.28;
- Android MobiAPParc v0 – v2.42.
INCIBE has coordinated the disclosure of a high-severity vulnerability affecting SMAP’s MobiAPParc, an app that enables users to pay for parking in regulated parking zones and in municipal car parks managed by Palma City Council. The vulnerability was discovered by Llorenç Romá.
This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:
- CVE-2026-14850: CVSS v4.0: 8.8 | CVSS AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H | CWE-640
The vulnerability has been fixed by the SMAP team in the latest version of the app.
CVE-2026-14850: the password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-14850 | Alta | No | SMAP |


