Description


Traccar 5.7 through 6.16.0 contains a cross-site request forgery vulnerability that allows attackers to log victims into attacker-controlled accounts because the OpenID Connect callback never validates the OAuth state parameter. Attackers can induce a victim's browser to load /api/session/openid/callback with their own authorization code, causing data the victim enters, such as registered devices, to land in the attacker's account.

Related CPE's


Could not find any relations

Weaknesses



CWE-352

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

4.2 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-11T13:17:18.220Z

1 hour ago

Last modified

2026-10-11T13:17:18.337Z

1 hour ago