PatchSiren cyber security CVE debrief
CVE-2026-108738 Traccar CVE debrief
The CVE-2026-108738 vulnerability in Traccar 5.7 through 6.16.0 allows attackers to log victims into attacker-controlled accounts via cross-site request forgery. The OpenID Connect callback never validates the OAuth state parameter, enabling attackers to induce a victim's browser to load /api/session/openid/callback with their own authorization code. This causes data the victim enters, such as registered devices, to land in the attacker's account. Defenders should prioritize verifying Traccar installations, assessing exposure, and implementing necessary security measures. The CVE record was published on 2026-10-11T12:19:43.602Z and has not been modified since then. AI-assisted debr
- Vendor
- Traccar
- Product
- Unknown
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for Traccar installations should assess exposure to potential cross-site request forgery attacks and implement necessary security measures. This includes verifying Traccar installations, prioritizing vulnerability management, and ensuring that security teams are aware of the potential risks. Operators, platform administrators, and security teams should collaborate to address this vulnerability and prevent potential exploitation.
Why it matters
The CVE-2026-108738 vulnerability in Traccar 5.7 through 6.16.0 allows attackers to log victims into attacker-controlled accounts via cross-site request forgery. Defenders should prioritize verifying Traccar installations, assessing exposure, and implementing necessary security measures.
- Attackers can induce a victim's browser to load /api/session/openid/callback with their own authorization code, causing data the victim enters to land in the attacker's account
- Defenders must verify Traccar installations to assess exposure to potential cross-site request forgery attacks
- Defenders should implement validation of the OAuth state parameter in the OpenID Connect callback to prevent exploitation
Technical summary
The Traccar 5.7 through 6.16.0 contains a cross-site request forgery vulnerability that allows attackers to log victims into attacker-controlled accounts because the OpenID Connect callback never validates the OAuth state parameter. Attackers can induce a victim's browser to load /api/session/openid/callback with their own authorization code, causing data the victim enters to land in the attacker's account. This vulnerability enables attackers to access and manipulate victim-entered data, such as registered devices, without their knowledge or consent.
Defensive priority
Defenders should prioritize verifying Traccar installations and assessing exposure to potential cross-site request forgery attacks.
Recommended defensive actions
- Verify Traccar installations to assess exposure to potential cross-site request forgery attacks
- Implement validation of the OAuth state parameter in the OpenID Connect callback
- Monitor for suspicious login activity and implement additional security measures as needed
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the cross-site request forgery vulnerability in Traccar 5.7 through 6.16.0. The OpenID Connect callback never validates the OAuth state parameter, allowing attackers to log victims into attacker-controlled accounts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108738 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108738
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108738 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108738
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Traccar 5.7 through 6.16.0 Login CSRF via OpenID Connect Callback
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108738.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind/traccar-oidc-client-missing-state-login-csrf
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/traccar/traccar/blob/cfab560c79ee9c9eaa41c79c6df351e820d6284b/src/main/java/org/traccar/database/OpenIdProvider.java
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/traccar/traccar/blob/cfab560c79ee9c9eaa41c79c6df351e820d6284b/src/main/java/org/traccar/api/resource/SessionResource.java
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/traccar/traccar
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/traccar-5.7-through-6.16.0-login-csrf-via-openid-connect-callback
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.