CVE-2026-78863

A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. The manipulation results in improper authentication. The attack may be performed from remote. Upgrading to version 3.1.0 is recommended to address this issue. Upgrading the affected component is recommended.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-25 11:16

Updated : 2026-08-27 17:20


NVD link : CVE-2026-78863

Mitre link : CVE-2026-78863

CVE.ORG link : CVE-2026-78863


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication