CVE-2026-78885
A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/s
CVSS
5.6
Medium
EPSS
0.4%
p29
KEV
—
Exploit Today
9
0-100
Published: Aug 25, 2026 · Last modified: Aug 27, 2026 · CWE-287
Not enough EPSS history yet.
A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC Service. Such manipulation leads to improper authentication. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. Upgrading to version 3.1.0 is sufficient to resolve this issue. Upgrading the affected component is advised.
- github.comhttps://github.com/liketrek/TREK/releases/tag/v3.1.0
- github.comhttps://github.com/mauriceboe/TREK/security/advisories/GHSA-fvgw-r58q-4cw4
- vuldb.comhttps://vuldb.com/cve/CVE-2026-78885
- vuldb.comhttps://vuldb.com/submit/886931
- vuldb.comhttps://vuldb.com/vuln/394941
- vuldb.comhttps://vuldb.com/vuln/394941/cti