Information Disclosure Vulnerability in TREK Collaborative Travel Planner
CVE-2026-54509

6.5MEDIUM

Key Information:

Vendor

Mauriceboe

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-54509?

A vulnerability exists in the TREK Collaborative Travel Planner affecting versions 3.0.0 to 3.1.0. In this specific version, the API route for sharing journeys does not adequately verify whether the authenticated user is authorized to access the requested journey. Consequently, an authenticated user can exploit this flaw by enumerating journey IDs, allowing them to retrieve tokens linked to other users' journeys. These tokens enable unauthorized access to various shared journey details, including entries, captions, moods, and gallery photos. This vulnerability poses significant risks to user privacy and data confidentiality, and it has been addressed in version 3.1.0.

Affected Version(s)

TREK >= 3.0.0, < 3.1.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.