Open Source GPS Tracking System Vulnerability in Traccar
CVE-2026-44314
5.3MEDIUM
What is CVE-2026-44314?
Traccar, an open source GPS tracking system, has a significant vulnerability that allows unauthorized users to upload and replace a device's stored image file. This occurs before version 6.13.0, specifically in the DeviceResource.uploadImage function, which bypasses essential permission checks. Unlike other update pathways that enforce access restrictions, this specific route neglects to invoke the permission verification steps, enabling non-admin users to modify device images. This flaw can potentially disrupt workflows that depend on the integrity of device media files, posing risks to system functionality and security.
Affected Version(s)
traccar < 6.13.0
