PT-2026-81298 · Unknown · Liketrek Trek

·

CVE-2026-78887

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions liketrek TREK versions prior to 3.1.0
Description An issue exists in the Journey Photo Proxy component where the validateShareTokenForAsset() function can be manipulated. This flaw allows a remote attacker to achieve incorrect authorization, although the attack is characterized by high complexity and is difficult to exploit.
Recommendations Upgrade to version 3.1.0.

Exploit

Fix

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78887
GHSA-24X9-FCJ9-VP6W

Affected Products

Liketrek Trek