MEDIUMCVSS 6.3Vulnerability

CVE-2026-78863

A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. The manipulation results in improper authentication. The attack may be performed from remote. Upgrading to version 3.1.0 is recommended to address this issue. Upgrading the affected component is recommended.

Properties

severity
MEDIUM
cvss_score
6.3
cvss_severity
MEDIUM
retrieved_at
2026-09-29T00:56:27+00:00
score
6.3
last_source
NVD
cve_id
CVE-2026-78863
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
signal_observed_at
2026-09-29T00:56:27+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
published_at
2026-08-25T11:16:54.627
last_modified
2026-09-28T23:10:00.143

Related Entities (2)

HAS_WEAKNESS (1)

→[Weakness]Improper Authentication

DESCRIBED_BY (1)

→[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-78863 (CVSS 6.3) — Ninja Signal Threat Intelligence | Ninja Signal