CSV Export Vulnerability in Traccar GPS Tracking System
CVE-2026-27644

6.5MEDIUM

Key Information:

Vendor

Traccar

Status
Vendor
CVE Published:
5 May 2026

What is CVE-2026-27644?

The Traccar GPS tracking system's CSV export feature, in versions 6.11.1 to 6.13.0, is susceptible to manipulation due to improper escaping of user-input data in output files. This flaw allows an attacker to embed malicious spreadsheet formulas within the exported CSV, which may execute commands or exfiltrate sensitive data upon opening the file in spreadsheet software. The vulnerability has been addressed in version 6.13.0, emphasizing the necessity for users to update and secure their installations.

Affected Version(s)

traccar >= 6.11.1 , < 6.13.0

traccar >= 6.11.1 , < 6.13.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.