CVE-2026-48745: Traccar Client: silent configuration hijack via unverified deep link redirects all GPS telemetry

Published Jun 16, 2026
·
Updated

Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a custom org.traccar.client://config deep-link scheme that silently writes attacker-supplied parameters (server URL, device ID, accuracy, distance, and interval) into the app's persistent configuration with no confirmation, notification, or visual indication. A single crafted link delivered via SMS, email, a webpage, or any installed app can therefore reconfigure the app the moment the victim taps it, with no special permissions required. As a result, an attacker can covertly redirect all of the victim's GPS telemetry to their own server at maximum precision and frequency, and the change persists across restarts. This gives the attacker continuous, real-time tracking of the victim's location. This issue has been fixed in version 9.7.20.

Affected Software

1 affected component
Traccar Traccar Client<=9.7.19

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Traccar Client to a version that resolves this vulnerability.

    Fixed in 9.7.20
  2. Compensating control

    Do not open or follow untrusted deep links (org.traccar.client://config). Block or filter messages/web content that contain org.traccar.client://config deep links and advise users to avoid tapping such links from SMS, email, webpages, or other apps until devices are updated.

  3. Operational

    Inspect the Traccar Client persistent configuration and restore any malicious changes. Specifically verify the server URL, device ID, accuracy, distance, and interval settings and reset them to intended values. If you cannot confirm integrity of these settings, reset the app configuration or reinstall the app and reconfigure from a known-good backup.

Event History

Jun 16, 2026
CVE Published
via MITRE·10:19 PM
Data Sourced
via MITRE·10:19 PM
DescriptionSeverityWeakness
Jun 17, 2026
Data Sourced
via NVD·01:20 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-48745?

CVE-2026-48745 has a critical severity rating of 9.3.

2

How do I fix CVE-2026-48745?

To fix CVE-2026-48745, update the Traccar Client to version 9.7.20 or later.

3

What is the impact of CVE-2026-48745?

CVE-2026-48745 allows an attacker to silently hijack GPS telemetry and redirect it to a malicious server.

4

Which versions of Traccar Client are affected by CVE-2026-48745?

Traccar Client versions 9.7.19 and below are affected by CVE-2026-48745.

5

How does CVE-2026-48745 exploit deep link redirects?

CVE-2026-48745 exploits unverified deep link redirects to compromise GPS tracking parameters.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203