PT-2026-95061 · Traccar · Traccar

·

CVE-2026-52851

·

Published

2026-05-29

·

Updated

2026-09-17

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Traccar versions prior to 6.14.0
Description An authenticated, non-readonly user can exploit a flaw when submitting requests to the 'DELETE /api/permissions' endpoint. The Permission(LinkedHashMap<String, Long>) function in src/main/java/org/traccar/model/Permission.java only validates the first two keys of the provided JSON, while the DatabaseStorage.removePermission() function in src/main/java/org/traccar/storage/DatabaseStorage.java concatenates all map keys into the SQL WHERE clause as column identifiers. This allows an attacker to inject controlled SQL via an extra JSON key, creating a blind boolean or error oracle. This can be used to extract sensitive database values, such as administrator emails, password hashes, and salts, or to conditionally delete permission rows.
Recommendations Update to version 6.14.0.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15030
CVE-2026-52851
GHSA-JX5H-FXHC-CC9W

Affected Products

Traccar