Traccar through 6.16.0 contains a weak password recovery vulnerability that allows attackers to reuse password reset tokens as session credentials because TokenManager does not bind tokens to a purpose. Attackers holding a leaked reset link can obtain a full session via /api/session or change passwords via /api/password/update, retaining access for seven days even after the victim resets their password.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Traccar through 6.16.0 contains a weak password recovery vulnerability that allows attackers to reuse password reset tokens as session credentials because TokenManager does not bind tokens to a purpose. Attackers holding a leaked reset link can obtain a full session via /api/session or change passwords via /api/password/update, retaining access for seven days even after the victim resets their password. | |
| Title | Traccar through 6.16.0 Weak Password Recovery via TokenManager Token Purpose Confusion | |
| First Time appeared |
Traccar
Traccar traccar |
|
| Weaknesses | CWE-640 | |
| CPEs | cpe:2.3:a:traccar:traccar:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Traccar
Traccar traccar |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:42.967Z
Reserved: 2026-10-11T01:52:49.949Z
Link: CVE-2026-108737
No data.
Status : Deferred
Published: 2026-10-11T13:17:18.053
Modified: 2026-10-11T13:17:18.173
Link: CVE-2026-108737
No data.
OpenCVE Enrichment
No data.
Weaknesses