PT-2026-44554 · Trek · Trek

CVE-2026-45410

·

Published

2026-05-28

·

Updated

2026-07-21

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions TREK versions prior to 3.0.18
Description An issue in the login flow allows an attacker to enumerate valid user accounts by analyzing response timing discrepancies. When a provided email address exists in the database, the backend executes a bcrypt password comparison—a computationally expensive hashing function used to secure passwords—before returning a 401 Unauthorized response, which introduces approximately 370 ms of latency. Conversely, if the email does not exist, the system returns a response almost immediately (approximately 10 ms). This significant timing difference enables the identification of registered users even when HTTP status codes and response bodies remain identical.
Recommendations Update to version 3.0.18.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45410
GHSA-3552-3C98-X79R

Affected Products

Trek