Impact
Traccar 5.7 through 6.16.0 contains a vulnerability that allows an attacker to cause a victim's browser to invoke the OpenID Connect callback with a forged authorization code. Because the state parameter is never validated, request creates a session that logs the victim into the attacker's account. As a result, any data and devices the victim enters in that session are stored under the attacker's account, effectively permitting the attacker to hijack the victim’s session and access the victim’s tracked devices.
Affected Systems
The vulnerability applies to installations of Traccar version 5.7 up to and including 6.16.0. No other Traccar releases are listed as affected, so versions outside this range are presumed not impacted.
Risk and Exploitability
The CVSS score is 2.3, indicating a low‑severity CSRF flaw that simply changes the account a user is logged into. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited or considered a top threat. The attack requires the victim to load a constructed callback URL (e.g., by following a link or loading a malicious page), and no additional external privileges are needed beyond the victim’s active session in the browser. The vulnerability is therefore limited to the attacker gaining control of the victim’s session within the scope of the affected Traccar deployment.
OpenCVE Enrichment