Medium severity4.2NVD Advisory· Published Oct 11, 2026· Updated Oct 11, 2026
CVE-2026-108738
CVE-2026-108738
Description
Traccar 5.7 through 6.16.0 contains a cross-site request forgery vulnerability that allows attackers to log victims into attacker-controlled accounts because the OpenID Connect callback never validates the OAuth state parameter. Attackers can induce a victim's browser to load /api/session/openid/callback with their own authorization code, causing data the victim enters, such as registered devices, to land in the attacker's account.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/traccar/traccar/blob/cfab560c79ee9c9eaa41c79c6df351e820d6284b/src/main/java/org/traccar/api/resource/SessionResource.javanvd
- github.com/traccar/traccar/blob/cfab560c79ee9c9eaa41c79c6df351e820d6284b/src/main/java/org/traccar/database/OpenIdProvider.javanvd
- hackmd.io/@haind/traccar-oidc-client-missing-state-login-csrfnvd
- www.vulncheck.com/advisories/traccar-5.7-through-6.16.0-login-csrf-via-openid-connect-callbacknvd
News mentions
0No linked articles in our index yet.