CRITICAL 9.3 NVD

CVE-2026-93556

The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for th

The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account.

References

Published: 2026-09-22 · Source: NVD · Feed updated: 2026-09-22
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-22 via NVD.

Risk Timeline

CVE Disclosed2026-09-22 · -1 days ago

Remediation Resources

vulnfeed aggregates 14151 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.