Description
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation can lead to incorrect authorization. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is said to be difficult. Upgrading to version 3.1.0 will fix this issue. You should upgrade the affected component.
Published: 2026-08-25
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Journey Photo Proxy component of liketrek TREK allows an attacker to manipulate the validateShareTokenForAsset function, causing the system to fail to enforce proper authorization. This weakness is an example of improper authorization (CWE‑285) and improper use of shared resources (CWE‑863). Malicious actors can obtain access to assets or services that should be restricted, potentially exposing sensitive media or personal data.

Affected Systems

This flaw exists in all installations of liketrek TREK versions up through 3.0.22. Version 3.1.0 incorporates a fix and is not affected. Users running 3.0.22 or earlier are at risk.

Risk and Exploitability

The CVSS score of 6.3 classifies this as a moderate severity issue. Exploitation can be performed remotely, and the description notes high complexity and difficulty, indicating that a skilled attacker must carefully construct the exploit. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited or no known active exploitation in the wild.

Generated by OpenCVE AI on August 25, 2026 at 15:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade liketrek TREK to version 3.1.0 or newer to apply the vendor-supplied fix.
  • If an immediate upgrade is not possible, restrict network access to the Journey Photo Proxy API to trusted hosts or through VPN to reduce exposure.
  • Enforce strict validation of share tokens on the server side, ensuring tokens are checked against the owning user's permissions before any asset is served.

Generated by OpenCVE AI on August 25, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation can lead to incorrect authorization. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is said to be difficult. Upgrading to version 3.1.0 will fix this issue. You should upgrade the affected component.
Title liketrek TREK Journey Photo Proxy validateShareTokenForAsset authorization
First Time appeared Liketrek
Liketrek trek
Weaknesses CWE-285
CWE-863
CPEs cpe:2.3:a:liketrek:trek:*:*:*:*:*:*:*:*
Vendors & Products Liketrek
Liketrek trek
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-25T12:45:10.723Z

Reserved: 2026-08-25T06:01:30.480Z

Link: CVE-2026-78887

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T13:19:32.233

Modified: 2026-08-25T13:19:32.233

Link: CVE-2026-78887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T15:30:05Z

Weaknesses