Cyclic Group-Parent Hierarchy Vulnerability in Traccar GPS Tracking System
CVE-2026-52852

6.5MEDIUM

Key Information:

Vendor

Traccar

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-52852?

In the Traccar GPS tracking system versions prior to 6.14.0, an authenticated user with group management permissions may create a cyclic group-parent hierarchy. This configuration can result in a failure to terminate requests, causing significant CPU usage on the server. The resulting high CPU utilization impacts system performance by exhausting web/API worker resources, particularly after repeated requests. This issue arises from the lack of cycle detection within the processing of group resources, which would typically prevent such scenarios. Notably, the problem has been addressed in version 6.14.0.

Affected Version(s)

traccar < 6.14.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.