CVE-2026-78885

Summary

A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC Service. Such manipulation leads to improper authentication. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. Upgrading to version 3.1.0 is sufficient to resolve this issue. Upgrading the affected component is advised.

Affected Software

VendorProductVersion RangeStatus
liketrekTREK3.0.0affected
liketrekTREK3.0.1affected
liketrekTREK3.0.2affected
liketrekTREK3.0.3affected
liketrekTREK3.0.4affected
liketrekTREK3.0.5affected
liketrekTREK3.0.6affected
liketrekTREK3.0.7affected
liketrekTREK3.0.8affected
liketrekTREK3.0.9affected
liketrekTREK3.0.10affected
liketrekTREK3.0.11affected
liketrekTREK3.0.12affected
liketrekTREK3.0.13affected
liketrekTREK3.0.14affected
liketrekTREK3.0.15affected
liketrekTREK3.0.16affected
liketrekTREK3.0.17affected
liketrekTREK3.0.18affected
liketrekTREK3.0.19affected
liketrekTREK3.0.20affected
liketrekTREK3.0.21affected
liketrekTREK3.0.22affected
liketrekTREK3.1.0unaffected

Weaknesses

  • CWE-287: Improper Authentication

References