CVE-2026-25648Disclosure(traccar / traccar)

LOWCVSS 8.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch traccar traccar systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by uploading malicious SVG files as device images. The application accepts SVG file uploads without sanitization and serves them with the `image/svg+xml` Content-Type, allowing embedded JavaScript to execute when victims view the image. As of time of publication, it is unclear whether a fix is available.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traccar

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 9 signals
  • Disclosure: 8 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-02-23); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
traccar

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-02-23: 4Mentions · 2026-02-24: 2Mentions · 2026-02-25: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1PoC Mentioned / Linked · 2026-02-25: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-23: 4Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 102-2302-2402-2502-2702-28
Signal classification2 categories
Disclosure
888.9%
General
111.1%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-02-234
Disclosure4
2026-02-242
Disclosure2
2026-02-251
Disclosure1
2026-02-271
Disclosure1
2026-02-281
General1
Full discourse9 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25648 Cross-Site Scripting in Traccar GPS Tracking System via Unsanitized SVG ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25648 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new XSS vulnerability (CVE‑2026‑25648) in Traccar GPS Tracking System via unsanitized SVG is disclosed, with links to vulnerability details and a notification.

    0002056
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25648: HIGH] Traccar system versions from 6.11.1 onwards have a security flaw allowing authenticated users to execute JavaScript via malicious SVG uploads. No fix is currently confirmed.#cve,CVE-2026-25648,#cybersecurity https://cvefind.com/CVE-2026-25648

    Post summary

    Traccar versions 6.11.1 and newer contain a flaw that allows authenticated users to execute JavaScript through malicious SVG uploads; no fix has been confirmed.

    0001064
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-25648** pertains to a security flaw in **Traccar**, an open-source GPS tracking system, specifically starting from version **6.11.1**. The vulnerability arises from the application's handling of SVG image uploads, where **authenticated users** can upload malicious SVG files containing embedded JavaScript. These files are then served to other users without sanitization, enabling **arbitrary JavaScript execution** within the context of other users' browsers. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #XSS https://cvetodo.com/cve/CVE-2026-25648

    Post summary

    The CVE describes an XSS vulnerability in Traccar where authenticated users can upload malicious SVG files that execute arbitrary JavaScript in other users' browsers.

    0001063
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-25648 - High Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' brow... https://www.thehackerwire.com/vulnerability/CVE-2026-25648/ https://t.co/tI8afrBq5T

    Post summary

    The post announces CVE-2026-25648, a high‑severity flaw in Traccar that allows authenticated users to execute arbitrary JavaScript in other users’ browsers.

    0001068
    113 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-25648 (CVSS:8.7, HIGH) is Analyzed. Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated use..https://nvd.nist.gov/vuln/detail/CVE-2026-25648 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet references CVE-2026-25648, noting its CVSS score and affected Traccar versions, but offers no PoC, exploit details, or patch information.

    0000031
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25648 (CVSS:8.7, HIGH) is Analyzed. Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated use..https://nvd.nist.gov/vuln/detail/CVE-2026-25648 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The text reports the analysis of CVE-2026-25648, noting its high severity and affected Traccar GPS tracking system versions, but provides no evidence of exploits or patches.

    0000021
    173 followersView on X
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 25, 2026 1. CVE-2026-3057: SQL Injection in pearProjectApi Backend Task.php dateTotalForProject A remote SQL injection vulnerability exists in the dateTotalForProject function of pearProjectApi up to version 2.8.10, allowing attackers to manipulate the projectCode argument. The exploit is publicly available, increasing the risk of unauthorized data access or modification. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-3057 2. Critical Remote Code Execution Vulnerabilities Found in SolarWinds Serv-U Multiple critical remote code execution vulnerabilities, including IDOR, type confusion, and broken access control, have been discovered in SolarWinds Serv-U. These flaws allow attackers with administrative privileges to execute arbitrary code or create privileged accounts, posing significant risks especially in environments where services run with elevated rights. Sources: Crowdstrike, Cvefeed, Darkreading, Gbhackers, Malwarebytes, Microsoft, Securityaffairs, Securityweek https://cvefeed.io/vuln/detail/CVE-2025-40541 3. Multiple Critical Vulnerabilities Discovered in Traccar GPS Tracking System Traccar versions up to 6.11.1 are affected by several critical security flaws including stored XSS via malicious SVG uploads, path traversal allowing arbitrary file writes, Cross-Site WebSocket Hijacking due to missing origin validation, and OAuth 2.0 authorization code theft through open redirect vulnerabilities. These issues allow authenticated attackers to execute arbitrary scripts, manipulate files on the server, hijack WebSocket sessions, and steal sensitive authorization tokens, posing significant risks to user data and system integrity. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-25648 4. Critical Vulnerabilities in Parse Dashboard AI Agent Endpoint Allow Unauthorized Access and CSRF Attacks Multiple vulnerabilities in Parse Dashboard versions 7.3.0-alpha.42 through 9.0.0-alpha.7 affect the AI Agent API endpoint, including missing CSRF protection, lack of authorization enforcement, and incomplete authentication. These flaws enable attackers to perform unauthorized actions, escalate privileges, and potentially access any connected Parse Server database using the master key. The issues have been addressed starting from version 9.0.0-alpha.8. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-27609 5. Ransomware Attacks on Romania and Mississippi Highlight Growing Threat to Critical Infrastructure Ransomware campaigns targeting Romania's critical infrastructure are reportedly linked to Russian geopolitical strategies, indicating a hybrid warfare approach. Separately, a ransomware attack on the University of Mississippi Medical Center forced closure of all clinics and cancellation of procedures, demonstrating the severe operational impact on healthcare services. Sources: Feedburner, Gbhackers, Infosecurity-Magazine, Sans, Securityweek, Therecord https://therecord.media/ransomware-gangs-advancing-moscow-geopolitical-interests-warns-romania Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article announces several newly disclosed vulnerabilities, providing technical details and noting that at least one has been patched, but does not report active exploitation or provide exploit code.

    0000037
    54 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Traccar` is vulnerable to stored XSS (CVE-2026-25648) via malicious SVG file uploads. This could lead to session hijacking within the web UI. Monitor for security updates. #Traccar #XSS #infosec https://www.pulsepatch.io/posts/cve-2026-25648-traccar-stored-xss-svg-upload

    Post summary

    Traccar is vulnerable to stored XSS through malicious SVG uploads, which could lead to session hijacking; users should monitor for security updates.

    0000050
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25648 Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the con… https://www.cve.org/CVERecord?id=CVE-2026-25648

    Post summary

    The CVE describes an authenticated JavaScript execution flaw in Traccar 6.11.1 and later, but no PoC, exploit, patch, or active exploitation details are provided.

    00000121
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptraccartraccar---

Explore more