Sceawere
Vulnerability Detail
CVE-2026-108737UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Traccar Improper Token Purpose Validation
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 4h ago
- Vendor
- Traccar
- Product
- Traccar
- Attack Type
- Weak Password Recovery Mechanism for Forgotten Password
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Traccar through 6.16.0 contains a weak password recovery vulnerability that allows attackers to reuse password reset tokens as session credentials because TokenManager does not bind tokens to a purpose. Attackers holding a leaked reset link can obtain a full session via /api/session or change passwords via /api/password/update, retaining access for seven days even after the victim resets their password.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-11T13:17:18.053Z",
"pubdate": "2026-10-11T13:17:18.053Z",
"executiveSummary": "Traccar versions through 6.16.0 are susceptible to an authentication bypass vulnerability rooted in improper cryptographic token lifecycle management. The vulnerability exists within the TokenManager component, which fails to cryptographically bind password reset tokens to a specific functional purpose. Consequently, these tokens are treated as generic authentication artifacts that can be interchanged across different API endpoints.\nAn attacker in possession of a leaked or intercepted password reset token can leverage it to gain unauthorized session access via the /api/session endpoint or modify user credentials via the /api/password/update endpoint. The impact is significant, as the resulting session persists for a seven-day window, effectively bypassing security measures such as password changes performed by the legitimate user. This flaw grants attackers persistent account control, bypassing standard authorization workflows. The exploitation does not require the attacker to compromise the victim's original credentials, only the ability to capture the transit-based reset token. Organizations utilizing Traccar should prioritize remediation to prevent unauthorized administrative or user account takeover.",
"technicalDetails": "The vulnerability resides in the TokenManager, the internal service responsible for generating, storing, and validating tokens within the Traccar architecture. The root cause is the lack of domain or purpose-binding for generated tokens. In a secure implementation, tokens utilized for ephemeral operations, such as password recovery, should be scoped to a single action and invalidated immediately upon usage or after a narrow time-to-live (TTL) expiration.\nIn Traccar, the TokenManager validates the authenticity of a token without verifying if that token was explicitly authorized for the specific API endpoint invoked by the client. Specifically, the system fails to differentiate between a token intended for the password recovery flow and one required for session authentication. This lack of logical separation permits the reuse of password reset tokens as valid session credentials.\nThe attack flow proceeds as follows: First, an attacker obtains a valid password reset token, which is typically sent via email to a user following a recovery request. If this link is intercepted—through man-in-the-middle (MITM) attacks, log analysis, or browser history leakage—the attacker gains the token. Second, the attacker presents this token to the /api/session endpoint. Because the TokenManager validates the token's signature without checking its intended purpose, the API returns an authenticated session object, granting the attacker the identity and privileges of the victim.\nAlternatively, the attacker may submit the token to the /api/password/update endpoint to set a new password. A critical post-exploitation concern is that the session established via the reset token persists for seven days. Even if the victim completes the password reset process, the attacker’s pre-established session remains active until the seven-day window expires. This behavior effectively invalidates the security benefit of the password change, as the attacker retains an 'evergreen' access window regardless of the user's remediation efforts. The vulnerability affects all versions of Traccar up to and including 6.16.0, as the logic does not impose a mandatory state-check between token generation and endpoint execution, resulting in a full bypass of authentication controls."
}