PT-2026-79196 · Trek · Trek
CVE-2026-62945
·
Published
2026-08-20
·
Updated
2026-08-21
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TREK versions prior to 3.1.3
Description
An authenticated user with file-edit permissions can disclose the existence and titles of reservations across private trip boundaries. The application fails to use the
findForeignLinkTarget() function to verify that referenced objects belong to the file's trip during file upload, update, and link actions. An attacker can submit foreign identifiers via the following endpoints:- 'POST /api/trips/:tripId/files/:id/link'
- 'POST /api/trips/:tripId/files'
- 'PUT /api/trips/:tripId/files/:id'
By manipulating the
reservation id, place id, or assignment id variables, the attacker can cause subsequent reads through FILE SELECT or the getFileLinks() function to return the reservation title of foreign reservations.Recommendations
Update to version 3.1.3.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trek