PT-2026-45077 · Unknown · Traccar-Client

·

CVE-2026-48745

·

Published

2026-05-30

·

Updated

2026-06-17

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Traccar Client versions prior to 9.7.20
Description The application registers a custom org.traccar.client://config deep-link scheme that allows the silent modification of persistent configuration settings without user confirmation or notification. An attacker can use a crafted link delivered via SMS, email, a webpage, or another app to hijack GPS tracking parameters, including the server URL, device ID, accuracy, distance, and interval. This enables the covert redirection of real-time GPS telemetry to an attacker-controlled server at maximum precision and frequency, with the changes persisting across device restarts.
Recommendations Update to version 9.7.20.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48745
GHSA-VM6J-6G39-GJ97

Affected Products

Traccar-Client