CVE-2026-40184: Unauthenticated Access to Uploaded Files in TREK
Published Apr 10, 2026
·Updated
TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. This vulnerability is fixed in 2.7.2.
Affected Software
2 affected components
TREK TREK<2.7.2
Mauriceboe Trek<=2.7.1
Remediation
Event History
Apr 10, 2026
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40184?
CVE-2026-40184 is categorized as a high severity vulnerability due to the risk of unauthorized access to uploaded files.
2
How do I fix CVE-2026-40184?
To fix CVE-2026-40184, upgrade TREK to version 2.7.2 or later.
3
What does CVE-2026-40184 affect?
CVE-2026-40184 affects TREK versions prior to 2.7.2, allowing unauthenticated access to uploaded photos.
4
Can unpatched systems be exploited through CVE-2026-40184?
Yes, unpatched systems running TREK versions before 2.7.2 can be easily exploited by unauthorized users.
5
Is there a workaround for CVE-2026-40184 before upgrading?
There is no known workaround for CVE-2026-40184, and the only effective solution is to upgrade to version 2.7.2.