PT-2026-21566 · Traccar · Traccar
Djvirus9
·
Published
2026-02-23
·
Updated
2026-02-28
·
CVE-2026-25649
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Traccar versions up to and including 6.11.1
Description
The Traccar open-source GPS tracking system is affected by an issue where authenticated users can obtain OAuth 2.0 authorization codes through an open redirect flaw in two OpenID Connect (OIDC)-related endpoints. The
redirect uri parameter is not properly validated against a whitelist, allowing attackers to redirect authorization codes to URLs under their control. This can lead to account takeover on any application integrated with OAuth.Recommendations
Versions up to and including 6.11.1 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Traccar