PT-2026-21558 · Traccar · Traccar

Djvirus9

·

Published

2026-02-23

·

Updated

2026-02-26

·

CVE-2026-23521

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Traccar versions up to and including 6.11.1
Description The Traccar GPS tracking system is affected by an issue where authenticated users with device creation or editing privileges can manipulate the uniqueId parameter to specify an absolute file path. This allows writing files outside the intended media directory because the system does not adequately validate that the resolved path remains within the designated media root during device image uploads.
Recommendations Versions prior to 6.11.1 are recommended. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23521
GHSA-RC28-CVFC-CHQR

Affected Products

Traccar