Cross-Site Request Forgery in Traccar Product by Traccar
CVE-2026-108738
2.3LOW
What is CVE-2026-108738?
The Traccar application versions 5.7 through 6.16.0 are susceptible to a cross-site request forgery vulnerability. This flaw arises because the OpenID Connect callback fails to validate the OAuth state parameter, enabling attackers to manipulate a victim's session. By persuading the victim's browser to navigate to the malicious endpoint /api/session/openid/callback with an attacker-controlled authorization code, sensitive information such as registered devices can be redirected to the attacker's account, thereby compromising the victim's data.
Affected Version(s)
Traccar 5.7 <= 6.16.0
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
