CVE-2026-108738
LOW
2,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
4,2
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: none
Description
AI Translation Available
Traccar 5.7 through 6.16.0 contains a cross-site request forgery vulnerability that allows attackers to log victims into attacker-controlled accounts because the OpenID Connect callback never validates the OAuth state parameter. Attackers can induce a victim's browser to load /api/session/openid/callback with their own authorization code, causing data the victim enters, such as registered devices, to land in the attacker's account.
352
Cross-Site Request Forgery (CSRF)
StableCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Non-Repudiation
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Bypass Protection Mechanism
Read Application Data
Modify Application Data
Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies:
Web Based, Web Server
https://github.com/traccar/traccar
https://github.com/traccar/traccar/blob/cfab560c79ee9c9eaa41c79c6df351e820d6284…
https://github.com/traccar/traccar/blob/cfab560c79ee9c9eaa41c79c6df351e820d6284…
https://hackmd.io/@haind/traccar-oidc-client-missing-state-login-csrf
https://www.vulncheck.com/advisories/traccar-5.7-through-6.16.0-login-csrf-via-…