PT-2026-79196 · Trek · Trek

CVE-2026-62945

·

Published

2026-08-20

·

Updated

2026-08-21

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions TREK versions prior to 3.1.3
Description An authenticated user with file-edit permissions can disclose the existence and titles of reservations across private trip boundaries. The application fails to use the findForeignLinkTarget() function to verify that referenced objects belong to the file's trip during file upload, update, and link actions. An attacker can submit foreign identifiers via the following endpoints:
  • 'POST /api/trips/:tripId/files/:id/link'
  • 'POST /api/trips/:tripId/files'
  • 'PUT /api/trips/:tripId/files/:id'
By manipulating the reservation id, place id, or assignment id variables, the attacker can cause subsequent reads through FILE SELECT or the getFileLinks() function to return the reservation title of foreign reservations.
Recommendations Update to version 3.1.3.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62945
GHSA-R4CP-666P-8F69

Affected Products

Trek