Cyclic Group-Parent Hierarchy Vulnerability in Traccar GPS Tracking System
CVE-2026-52852
6.5MEDIUM
What is CVE-2026-52852?
In the Traccar GPS tracking system versions prior to 6.14.0, an authenticated user with group management permissions may create a cyclic group-parent hierarchy. This configuration can result in a failure to terminate requests, causing significant CPU usage on the server. The resulting high CPU utilization impacts system performance by exhausting web/API worker resources, particularly after repeated requests. This issue arises from the lack of cycle detection within the processing of group resources, which would typically prevent such scenarios. Notably, the problem has been addressed in version 6.14.0.
Affected Version(s)
traccar < 6.14.0
