The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
The vulnerability was fixed by the Kompini team on 25 November 2025.
Workaround
No workaround given by the vendor.
References
History
Tue, 22 Sep 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account. | |
| Title | Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-22T08:57:30.854Z
Reserved: 2026-09-18T09:33:15.572Z
Link: CVE-2026-93556
No data.
Status : Received
Published: 2026-09-22T09:17:05.800
Modified: 2026-09-22T09:17:05.800
Link: CVE-2026-93556
No data.
OpenCVE Enrichment
No data.
Weaknesses