CVE-2026-108738
Deferred Deferred - Pending Action

Cross-Site Request Forgery in Traccar

Vulnerability report for CVE-2026-108738, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Traccar 5.7 through 6.16.0 contains a cross-site request forgery vulnerability that allows attackers to log victims into attacker-controlled accounts because the OpenID Connect callback never validates the OAuth state parameter. Attackers can induce a victim's browser to load /api/session/openid/callback with their own authorization code, causing data the victim enters, such as registered devices, to land in the attacker's account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Traccar Traccar 5.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108738 is a Cross-Site Request Forgery (CSRF) vulnerability in Traccar versions 5.7 through 6.16.0. It occurs because the OpenID Connect callback does not validate the OAuth state parameter. Attackers exploit this by tricking victims into loading a malicious callback URL with an attacker-controlled authorization code, causing the victim to log into the attacker's account. Any data entered by the victim, such as device registrations, is then associated with the attacker's account.

Detection Guidance

To detect this vulnerability, check Traccar logs for unusual OpenID Connect callback requests. Look for repeated /api/session/openid/callback endpoints with mismatched authorization codes or missing state parameters. Monitor network traffic for unexpected redirects to attacker-controlled domains.

Impact Analysis

This vulnerability allows attackers to gain unauthorized access to your Traccar account. If you are tricked into visiting a malicious link, your session could be hijacked, and any data you enter, such as device information, could be transferred to the attacker's account. This could lead to loss of control over your tracked devices and sensitive data.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA compliance. GDPR requires protecting personal data, and HIPAA mandates safeguarding health-related information. A breach due to this vulnerability may result in data exposure, leading to legal penalties and reputational damage.

Mitigation Strategies
  • Upgrade Traccar to a version that validates the OAuth state parameter in the OpenID Connect callback.
  • Review and restrict access to the /api/session/openid/callback endpoint to prevent unauthorized requests.
  • Monitor user accounts for unauthorized device registrations or account associations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108738. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart