CVE-2026-78887
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-78887, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: VulDB

Description

A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation can lead to incorrect authorization. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is said to be difficult. Upgrading to version 3.1.0 will fix this issue. You should upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
liketrek trek to 3.0.22 (inc)
liketrek trek 3.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in liketrek TREK up to version 3.0.22, specifically in the Journey Photo Proxy component. It involves a flaw in the validateShareTokenForAsset function that allows incorrect authorization through remote manipulation. The attack requires high complexity and is difficult to exploit.

Detection Guidance

To detect this vulnerability, check if your TREK application version is below 3.1.0. Inspect the validateShareTokenForAsset function for improper authorization checks. Test by attempting to access assets outside shared journeys using valid tokens.

Impact Analysis

An attacker could exploit this to bypass authorization checks, potentially gaining unauthorized access to sensitive data or functions. The impact includes potential data exposure or unauthorized actions, though the complexity makes widespread exploitation less likely.

Compliance Impact

This vulnerability could lead to unauthorized access to private photos stored on connected servers, potentially exposing sensitive personal data. This may violate GDPR's data protection principles and HIPAA's requirements for safeguarding protected health information if such data is involved.

Mitigation Strategies

Upgrade the affected component, liketrek TREK, to version 3.1.0 or later to fix the vulnerability in the Journey Photo Proxy component.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78887. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart