CVE-2026-23521 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices…
Medium CVSS: 6.5

CVE-2026-23521

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absolute path. When uploading a device image, Traccar uses that `uniqueId` to build the filesystem path without enforcing that the resolved path stays under the media root. This allows writing files outside the media directory. As of time of publication, it is unclear whether a fix is available.
Vendor
Traccar
Product
Traccar
CWE
CWE-22
Yayın Tarihi
2026-02-23 21:19:09
Güncelleme
2026-02-26 16:27:57
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar