A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. The manipulation results in improper authentication. The attack may be performed from remote. Upgrading to version 3.1.0 is recommended to address this issue. Upgrading the affected component is recommended.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 11:16
Updated : 2026-08-27 17:20
NVD link : CVE-2026-78863
Mitre link : CVE-2026-78863
CVE.ORG link : CVE-2026-78863
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
