Sceawere
Vulnerability Detail
CVE-2026-108738UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Traccar OpenID CSRF Account Hijacking
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.2
- Creation Date
- 4h ago
- Vendor
- Traccar
- Product
- Traccar
- Attack Type
- Cross-Site Request Forgery (CSRF)
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Traccar 5.7 through 6.16.0 contains a cross-site request forgery vulnerability that allows attackers to log victims into attacker-controlled accounts because the OpenID Connect callback never validates the OAuth state parameter. Attackers can induce a victim's browser to load /api/session/openid/callback with their own authorization code, causing data the victim enters, such as registered devices, to land in the attacker's account.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.2",
"pubDate": "2026-10-11T13:17:18.220Z",
"pubdate": "2026-10-11T13:17:18.220Z",
"executiveSummary": "Traccar versions 5.7 through 6.16.0 are vulnerable to a Cross-Site Request Forgery (CSRF) vulnerability within the OpenID Connect (OIDC) authentication flow.\nThe vulnerability arises from the failure of the /api/session/openid/callback endpoint to validate the OAuth 'state' parameter during the authentication callback process.\nAn unauthenticated or remote attacker can force a victim's browser to execute an OIDC callback using an authorization code associated with an attacker-controlled account.\nSuccessful exploitation results in the victim's session being authenticated into the attacker's account, causing any subsequent data generated by the victim, such as device registrations or tracking information, to be stored within the attacker-managed database.\nThis flaw compromises the integrity and confidentiality of user telemetry data and poses a significant risk to the security posture of the Traccar installation by allowing unauthorized account association and potential data exfiltration via misleading session binding.\nNo specific user privileges are required for the victim, as the exploit relies on the browser's automatic handling of cookies and redirects when the victim is induced to navigate to the attacker-supplied callback URL.",
"technicalDetails": "The root cause of this vulnerability is an insecure implementation of the OpenID Connect flow within the Traccar application, specifically within the /api/session/openid/callback endpoint. In a standard OIDC implementation, the 'state' parameter is a mandatory security token used to maintain state between the authentication request and the callback, effectively serving as a CSRF protection mechanism.\nIn the affected versions (Traccar 5.7 through 6.16.0), the application fails to perform a cryptographic or equality check to ensure that the 'state' parameter returned by the OIDC provider matches the one initially generated during the initiation phase. This omission allows an attacker to inject an arbitrary or pre-recorded authorization code into the victim's session context.\nThe exploitation flow proceeds as follows: First, the attacker initiates an OIDC flow with the legitimate service provider using their own credentials, obtaining a valid authorization code. Instead of completing the process, the attacker crafts a malicious link or script that induces the victim's browser to send a GET request to the /api/session/openid/callback endpoint, including the attacker's authorization code as a query parameter.\nBecause the server lacks state validation, it processes the request as a legitimate login attempt for the victim, binding the victim's current browser session to the attacker's account. Once the victim is authenticated into the attacker's account, the victim’s client will proceed to interact with the Traccar interface, inadvertently sending telemetry data, device configurations, and proprietary tracking assets directly to the attacker's account context.\nThis vulnerability is particularly dangerous because it facilitates unauthorized data collection without requiring the victim to provide credentials. The attack is persistent, as the victim's browser maintains the authenticated session until explicitly terminated. The lack of state verification violates the OIDC specification (RFC 6749 and OIDC Core 1.0), which mandates that the client must verify the state parameter to prevent unauthorized session binding.\nThe affected component is the OAuth/OIDC integration logic in the Traccar backend. Any deployment utilizing external OIDC providers to manage user sessions is susceptible to this attack, regardless of network location, provided the victim can be induced to access the attacker-supplied callback link."
}