Description
Traccar 5.7 through 6.16.0 contains a cross-site request forgery vulnerability that allows attackers to log victims into attacker-controlled accounts because the OpenID Connect callback never validates the OAuth state parameter. Attackers can induce a victim's browser to load /api/session/openid/callback with their own authorization code, causing data the victim enters, such as registered devices, to land in the attacker's account.
Published: 2026-10-11
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Unauthorized Account Login
Action: Patch
AI Analysis

Impact

Traccar 5.7 through 6.16.0 contains a vulnerability that allows an attacker to cause a victim's browser to invoke the OpenID Connect callback with a forged authorization code. Because the state parameter is never validated, request creates a session that logs the victim into the attacker's account. As a result, any data and devices the victim enters in that session are stored under the attacker's account, effectively permitting the attacker to hijack the victim’s session and access the victim’s tracked devices.

Affected Systems

The vulnerability applies to installations of Traccar version 5.7 up to and including 6.16.0. No other Traccar releases are listed as affected, so versions outside this range are presumed not impacted.

Risk and Exploitability

The CVSS score is 2.3, indicating a low‑severity CSRF flaw that simply changes the account a user is logged into. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited or considered a top threat. The attack requires the victim to load a constructed callback URL (e.g., by following a link or loading a malicious page), and no additional external privileges are needed beyond the victim’s active session in the browser. The vulnerability is therefore limited to the attacker gaining control of the victim’s session within the scope of the affected Traccar deployment.

Generated by OpenCVE AI on October 11, 2026 at 13:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Traccar to a version that implements state validation in the OpenID Connect callback; consult the vendor’s release notes for the fix.
  • If an upgrade is not immediately feasible, disable or block external access to the /api/session/openid/callback endpoint to prevent attackers from manipulating the callback flow.
  • Configure any custom OpenID Connect setups to include and verify a state token, or restrict callbacks to trusted identity providers only.
  • Review the deployment to ensure no other CSRF‑prone endpoints remain exposed and enforce strict input validation for authentication callbacks.

Generated by OpenCVE AI on October 11, 2026 at 13:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Traccar 5.7 through 6.16.0 contains a cross-site request forgery vulnerability that allows attackers to log victims into attacker-controlled accounts because the OpenID Connect callback never validates the OAuth state parameter. Attackers can induce a victim's browser to load /api/session/openid/callback with their own authorization code, causing data the victim enters, such as registered devices, to land in the attacker's account.
Title Traccar 5.7 through 6.16.0 Login CSRF via OpenID Connect Callback
First Time appeared Traccar
Traccar traccar
Weaknesses CWE-352
CPEs cpe:2.3:a:traccar:traccar:*:*:*:*:*:*:*:*
Vendors & Products Traccar
Traccar traccar
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:43.602Z

Reserved: 2026-10-11T01:52:54.368Z

Link: CVE-2026-108738

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T13:17:18.220

Modified: 2026-10-11T13:17:18.337

Link: CVE-2026-108738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:45:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)