Path Traversal Vulnerability in Traccar GPS Tracking System by Traccar
CVE-2026-23521
6.5MEDIUM
What is CVE-2026-23521?
The Traccar GPS tracking system has a vulnerability that permits authenticated users to exploit the uniqueId parameter to specify an absolute filesystem path. This exploitation allows users to upload files outside the intended media directory by manipulating the filesystem access through the unresolved path, posing a significant security risk. As of the latest update, no patch is available for this issue.
Affected Version(s)
traccar <= 6.11.1
