CVE-2026-40185: Missing Authorization on Immich Trip Photo Routes in TREK
Published Apr 10, 2026
·Updated
TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo management routes. This vulnerability is fixed in 2.7.2.
Affected Software
2 affected components
TREK<2.7.2
Mauriceboe Trek Node.js<=2.7.1
Remediation
Event History
Apr 10, 2026
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40185?
CVE-2026-40185 is categorized as a medium severity vulnerability due to its potential impact on unauthorized access to user photos.
2
How do I fix CVE-2026-40185?
To fix CVE-2026-40185, upgrade to TREK version 2.7.2 or later where the missing authorization checks have been implemented.
3
What type of vulnerability is CVE-2026-40185?
CVE-2026-40185 is classified as a missing authorization vulnerability affecting the Immich trip photo management routes.
4
What versions of TREK are affected by CVE-2026-40185?
TREK versions prior to 2.7.2 are affected by CVE-2026-40185.
5
Can CVE-2026-40185 lead to data exposure?
Yes, CVE-2026-40185 can lead to unauthorized access and potential exposure of sensitive photo data.