Description
Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. Permission(LinkedHashMap<String, Long>) in src/main/java/org/traccar/model/Permission.java validates only the first two keys, but DatabaseStorage.removePermission() in src/main/java/org/traccar/storage/DatabaseStorage.java concatenates every map key into the SQL WHERE clause as a column identifier. The extra key therefore becomes attacker-controlled SQL and provides a blind boolean or error oracle that can extract arbitrary database values, including administrator email, password hashes, and salts, or conditionally delete permission rows. Unauthenticated requests are rejected. This issue is fixed in 6.14.0.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Blind SQL Injection allowing extraction of sensitive data and conditional deletion of permissions
Action: Apply Patch
AI Analysis

Impact

Authenticated users with permission editing capabilities can craft a DELETE /api/permissions request containing an extra JSON key. The application validates only the first two keys, but the underlying storage code concatenates every map key into the SQL WHERE clause, turning the attacker-controlled key into arbitrary SQL. This results in a blind boolean or error oracle against the database, from which an attacker can retrieve values such as administrator email addresses, password hashes, and salts, or cause selective deletion of permission rows. The flaw does not provide remote code execution but permits significant data exfiltration and privilege manipulation.

Affected Systems

The affected product is Traccar GPS tracking software, versions prior to 6.14.0. Users running any release older than 6.14.0 who possess non‑readonly permission editing privileges are vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium to high severity with significant impact on confidentiality and integrity. The EPSS score of less than 1% suggests a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication and a valid permission‑management session, so the attack vector is through authenticated API usage. If an attacker gains or hijacks a legitimate account with sufficient privileges, the blind oracle can be leveraged to enumerate database contents or delete permissions, potentially compromising the entire system. The risk remains moderate due to the adherence to authentication but high due to the depth of data that can be extracted once access is achieved.

Generated by OpenCVE AI on September 19, 2026 at 02:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Traccar to version 6.14.0 or later to apply the vendor patch
  • Restrict the DELETE /api/permissions endpoint to administrators only and enforce the minimum required roles for permission modifications
  • Audit existing permissions and remove any that are no longer needed, verifying that all non‑readonly operations follow least‑privilege principles

Generated by OpenCVE AI on September 19, 2026 at 02:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Traccar
Traccar traccar
Vendors & Products Traccar
Traccar traccar

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. Permission(LinkedHashMap<String, Long>) in src/main/java/org/traccar/model/Permission.java validates only the first two keys, but DatabaseStorage.removePermission() in src/main/java/org/traccar/storage/DatabaseStorage.java concatenates every map key into the SQL WHERE clause as a column identifier. The extra key therefore becomes attacker-controlled SQL and provides a blind boolean or error oracle that can extract arbitrary database values, including administrator email, password hashes, and salts, or conditionally delete permission rows. Unauthenticated requests are rejected. This issue is fixed in 6.14.0.
Title Traccar: Authenticated Blind SQL Injection in DELETE /api/permissions
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:05:00.756Z

Reserved: 2026-06-08T18:41:27.724Z

Link: CVE-2026-52851

cve-icon Vulnrichment

Updated: 2026-09-17T19:04:53.690Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T19:16:49.680

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-52851

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')