PT-2026-32037 · Mauriceboe · Trek

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-40185

CVSS v3.1

7.1

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo management routes. This vulnerability is fixed in 2.7.2.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-40185

Affected Products

Trek