CVE-2026-108737
Deferred Deferred - Pending Action

Weak Password Recovery in Traccar Allows Session Hijacking

Vulnerability report for CVE-2026-108737, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Traccar through 6.16.0 contains a weak password recovery vulnerability that allows attackers to reuse password reset tokens as session credentials because TokenManager does not bind tokens to a purpose. Attackers holding a leaked reset link can obtain a full session via /api/session or change passwords via /api/password/update, retaining access for seven days even after the victim resets their password.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Traccar Traccar 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108737 is a token purpose confusion vulnerability in Traccar through version 6.16.0. The system uses the same token format for multiple purposes like password resets, API sessions, and OIDC access without distinguishing between them. Attackers can exploit leaked password reset tokens to gain full session access or change passwords without completing the reset process. Tokens remain valid for seven days even after password changes because the system does not revoke them upon legitimate password updates.

Detection Guidance

Check Traccar logs for suspicious API session creation or password update requests via /api/session or /api/password/update endpoints. Monitor for tokens reused outside password reset contexts. Inspect TokenManager logs for tokens without purpose validation.

Impact Analysis

If you use Traccar, an attacker could gain unauthorized access to your account by reusing a leaked password reset token. They could take over your session, change your password, or access sensitive data. Even if you reset your password, the attacker may retain access for up to seven days. This could lead to data theft, account misuse, or further compromise of your tracking system.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. It may result in data breaches, unauthorized disclosures, or lack of user consent for data processing, potentially leading to regulatory fines or legal consequences.

Mitigation Strategies

Upgrade Traccar to a version beyond 6.16.0 where token purpose binding is implemented. Review and revoke all active tokens. Disable password reset links until patched. Monitor for unauthorized session creation or password changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108737. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart