MEDIUM 5.3 NVD
CVE-2026-78863
A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-
A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. The manipulation results in improper authentication. The attack may be performed from remote. Upgrading to version 3.1.0 is recommended to address this issue. Upgrading the affected component is recommended.
References
- https://github.com/liketrek/TREK/releases/tag/v3.1.0
- https://github.com/mauriceboe/TREK/security/advisories/GHSA-mjh4-w6fq-54qm
- https://vuldb.com/cve/CVE-2026-78863
- https://vuldb.com/submit/886929
- https://vuldb.com/vuln/394939
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-25 via NVD.
vulnfeed aggregates 12116 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.