Authorization Weakness in liketrek TREK Journey Photo Proxy Component
CVE-2026-78887
6.3MEDIUM
What is CVE-2026-78887?
A vulnerability has been discovered in the liketrek TREK application, specifically within the Journey Photo Proxy component, which may allow attackers to manipulate the validateShareTokenForAsset function. This vulnerability can result in incorrect authorization, potentially leading to unauthorized access. Although the complexity of executing this attack is considered high, it can be initiated remotely, making it a serious concern for users of affected versions. It is highly recommended to upgrade to TREK version 3.1.0 to address this issue and enhance security.
Affected Version(s)
TREK 3.0.0
TREK 3.0.1
TREK 3.0.2
