PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108738 Traccar CVE debrief

The CVE-2026-108738 vulnerability in Traccar 5.7 through 6.16.0 allows attackers to log victims into attacker-controlled accounts via cross-site request forgery. The OpenID Connect callback never validates the OAuth state parameter, enabling attackers to induce a victim's browser to load /api/session/openid/callback with their own authorization code. This causes data the victim enters, such as registered devices, to land in the attacker's account. Defenders should prioritize verifying Traccar installations, assessing exposure, and implementing necessary security measures. The CVE record was published on 2026-10-11T12:19:43.602Z and has not been modified since then. AI-assisted debr

Vendor
Traccar
Product
Unknown
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for Traccar installations should assess exposure to potential cross-site request forgery attacks and implement necessary security measures. This includes verifying Traccar installations, prioritizing vulnerability management, and ensuring that security teams are aware of the potential risks. Operators, platform administrators, and security teams should collaborate to address this vulnerability and prevent potential exploitation.

Why it matters

The CVE-2026-108738 vulnerability in Traccar 5.7 through 6.16.0 allows attackers to log victims into attacker-controlled accounts via cross-site request forgery. Defenders should prioritize verifying Traccar installations, assessing exposure, and implementing necessary security measures.

  • Attackers can induce a victim's browser to load /api/session/openid/callback with their own authorization code, causing data the victim enters to land in the attacker's account
  • Defenders must verify Traccar installations to assess exposure to potential cross-site request forgery attacks
  • Defenders should implement validation of the OAuth state parameter in the OpenID Connect callback to prevent exploitation

Technical summary

The Traccar 5.7 through 6.16.0 contains a cross-site request forgery vulnerability that allows attackers to log victims into attacker-controlled accounts because the OpenID Connect callback never validates the OAuth state parameter. Attackers can induce a victim's browser to load /api/session/openid/callback with their own authorization code, causing data the victim enters to land in the attacker's account. This vulnerability enables attackers to access and manipulate victim-entered data, such as registered devices, without their knowledge or consent.

Defensive priority

Defenders should prioritize verifying Traccar installations and assessing exposure to potential cross-site request forgery attacks.

Recommended defensive actions

  • Verify Traccar installations to assess exposure to potential cross-site request forgery attacks
  • Implement validation of the OAuth state parameter in the OpenID Connect callback
  • Monitor for suspicious login activity and implement additional security measures as needed
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the cross-site request forgery vulnerability in Traccar 5.7 through 6.16.0. The OpenID Connect callback never validates the OAuth state parameter, allowing attackers to log victims into attacker-controlled accounts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108738 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108738

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108738 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108738

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Traccar 5.7 through 6.16.0 Login CSRF via OpenID Connect Callback

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108738.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@haind/traccar-oidc-client-missing-state-login-csrf

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/traccar/traccar/blob/cfab560c79ee9c9eaa41c79c6df351e820d6284b/src/main/java/org/traccar/database/OpenIdProvider.java

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/traccar/traccar/blob/cfab560c79ee9c9eaa41c79c6df351e820d6284b/src/main/java/org/traccar/api/resource/SessionResource.java

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/traccar/traccar

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/traccar-5.7-through-6.16.0-login-csrf-via-openid-connect-callback

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.