Path Traversal Vulnerability in Traccar GPS Tracking System by Traccar
CVE-2026-23521

6.5MEDIUM

Key Information:

Vendor

Traccar

Status
Vendor
CVE Published:
23 February 2026

What is CVE-2026-23521?

The Traccar GPS tracking system has a vulnerability that permits authenticated users to exploit the uniqueId parameter to specify an absolute filesystem path. This exploitation allows users to upload files outside the intended media directory by manipulating the filesystem access through the unresolved path, posing a significant security risk. As of the latest update, no patch is available for this issue.

Affected Version(s)

traccar <= 6.11.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.