A AegiFlow
HIGHCVSS 8.8

CVE-2026-14850

CVE-2026-14850 updated by NVD

Published
2026-09-17
Modified
2026-09-20
Sources
euvd, nvd

Summary

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.

References

Includes data from the ENISA EU Vulnerability Database (EUVD).

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.