PT-2026-81264 · Unknown · Liketrek Trek

·

CVE-2026-78863

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions liketrek TREK versions prior to 3.1.0
Description Remote manipulation of the loginUser() function within the server/src/services/authService.ts file of the Pre-2FA mfa token Handler component leads to improper authentication.
Recommendations Update to version 3.1.0.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78863
GHSA-MJH4-W6FQ-54QM

Affected Products

Liketrek Trek