PatchSiren cyber security CVE debrief
CVE-2026-48745 traccar CVE debrief
The Traccar Client, a GPS tracking mobile app, is vulnerable to a critical issue (CVE-2026-48745) in versions 9.7.19 and below. A crafted deep link can silently hijack GPS tracking parameters, redirecting telemetry to an attacker-controlled server. This issue, with a CVSS score of 9.3, allows for continuous, real-time tracking of the victim's location without requiring special permissions. The vulnerability is fixed in version 9.7.20. Organizations and individuals using Traccar Client should update to the latest version to mitigate this risk.
- Vendor
- traccar
- Product
- traccar-client
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Organizations and individuals using Traccar Client versions 9.7.19 and below should be aware of this critical vulnerability. Updating to version 9.7.20 or later is essential to prevent potential location tracking by attackers.
Technical summary
The Traccar Client app for GPS tracking is vulnerable to a deep link hijacking issue. The app registers a custom 'org.traccar.client://config' deep-link scheme that can silently write attacker-supplied parameters into the app's configuration. This allows an attacker to redirect GPS telemetry to their server by crafting a single deep link, which can be delivered via SMS, email, or a webpage. The change persists across app restarts, enabling continuous tracking of the victim's location.
Defensive priority
Critical
Recommended defensive actions
- Update Traccar Client to version 9.7.20 or later
- Be cautious when clicking on links from unknown sources
- Use secure communication channels for sending location updates
- Monitor GPS tracking configurations for suspicious changes
- Implement additional security measures, such as two-factor authentication
- Regularly review and update mobile app configurations
- Consider using alternative GPS tracking solutions with enhanced security features
Evidence notes
The information provided is based on the CVE record and NVD details. The vulnerability was published on June 17, 2026, and modified on the same day. The issue was fixed in version 9.7.20, as mentioned in the CVE description.
Official resources
CVE-2026-48745 was published on June 17, 2026, and modified on the same day.