CVE-2026-25649Disclosure(traccar / traccar)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiting an open redirect vulnerability in two OIDC-related endpoints. The `redirect_uri` parameter is not validated against a whitelist, allowing attackers to redirect authorization codes to attacker-controlled URLs, enabling account takeover on any OAuth-integrated application. As of time of publication, it is unclear whether a fix is available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352CWE-601

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traccar

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-24); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
traccar

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-24: 2Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-28: 102-2402-2702-28
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure1General1
2026-02-271
General1
2026-02-281
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25649 OAuth 2.0 Authorization Code Theft Vulnerability in Traccar GPS Tracking System https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25649

    Post summary

    The text references CVE-2026-25649, an OAuth 2.0 authorization code theft vulnerability in Traccar GPS Tracking System, but provides no further details.

    0001041
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25649 (CVSS:7.3, HIGH) is Analyzed. Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticat..https://nvd.nist.gov/vuln/detail/CVE-2026-25649 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-25649, noting its CVSS score, affected Traccar GPS tracking system versions, and a brief indication that the flaw involves authentication.

    0000023
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-25649 (CVSS:7.3, HIGH) is Analyzed. Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticat..https://nvd.nist.gov/vuln/detail/CVE-2026-25649 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post identifies CVE-2026-25649 as a high‑CVSS vulnerability affecting Traccar up to version 6.11.1, but offers no additional exploitation, mitigation, or technical details.

    0000023
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25649 Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization cod… https://www.cve.org/CVERecord?id=CVE-2026-25649

    Post summary

    The CVE highlights that authenticated users can steal OAuth 2.0 authorization codes in Traccar up to version 6.11.1, but no PoC, exploit, patch, or active exploitation is mentioned.

    00000553
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptraccartraccar---

Explore more