PT-2026-21558 · Traccar · Traccar

Djvirus9

·

Publicado

2026-02-23

·

Atualizado

2026-02-26

·

CVE-2026-23521

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Traccar versions up to and including 6.11.1
Description The Traccar GPS tracking system is affected by an issue where authenticated users with device creation or editing privileges can manipulate the uniqueId parameter to specify an absolute file path. This allows writing files outside the intended media directory because the system does not adequately validate that the resolved path remains within the designated media root during device image uploads.
Recommendations Versions prior to 6.11.1 are recommended. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23521
GHSA-RC28-CVFC-CHQR

Produtos afetados

Traccar