MinorCritical vulnerability
CVE-2026-108737 (CVSS 7.6)
NVD · officialPublished Oct 11, 2026Risk 23/100
Traccar through 6.16.0 contains a weak password recovery vulnerability that allows attackers to reuse password reset tokens as session credentials because TokenManager does not bind tokens to a purpose. Attackers holding a leaked reset link can obtain a full session via /api/session or change passwords via /api/password/update, retaining access for seven days even after the victim resets their password.
Technical details
CVSS
7.6
AV:NetworkAC:LowPR:NoneUI:Passive
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source