Authorization Weakness in liketrek TREK Journey Photo Proxy Component
CVE-2026-78887

6.3MEDIUM

Key Information:

Vendor

Liketrek

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-78887?

A vulnerability has been discovered in the liketrek TREK application, specifically within the Journey Photo Proxy component, which may allow attackers to manipulate the validateShareTokenForAsset function. This vulnerability can result in incorrect authorization, potentially leading to unauthorized access. Although the complexity of executing this attack is considered high, it can be initiated remotely, making it a serious concern for users of affected versions. It is highly recommended to upgrade to TREK version 3.1.0 to address this issue and enhance security.

Affected Version(s)

TREK 3.0.0

TREK 3.0.1

TREK 3.0.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ByteJMP (VulDB User)
.