Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability was fixed by the Kompini team on 25 November 2025.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them to take control of the account. | |
| Title | Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-22T10:15:28.526Z
Reserved: 2026-09-18T09:33:15.572Z
Link: CVE-2026-93556
Updated: 2026-09-22T10:15:09.986Z
Status : Received
Published: 2026-09-22T09:17:05.800
Modified: 2026-09-22T11:17:26.790
Link: CVE-2026-93556
No data.
OpenCVE Enrichment
Updated: 2026-09-22T10:30:17Z
-
CWE-639
Authorization Bypass Through User-Controlled Key