Open Redirect Vulnerability in Traccar GPS Tracking System by Traccar
CVE-2026-25649

7.3HIGH

Key Information:

Vendor

Traccar

Status
Vendor
CVE Published:
23 February 2026

What is CVE-2026-25649?

Versions of the Traccar GPS tracking system up to 6.11.1 are susceptible to an open redirect vulnerability that allows authenticated users to exploit the redirect_uri parameter. By failing to validate this parameter against a whitelist, attackers can redirect OAuth 2.0 authorization codes to arbitrary, attacker-controlled URLs. This can lead to unauthorized account access in any application utilizing OAuth integration, compromising user accounts and sensitive data. As of the latest information available, a fix for this vulnerability is not publicly confirmed.

Affected Version(s)

traccar <= 6.11.1

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.