CVE-2026-62279: LubeLogger: IDOR in DuplicateRecordsToOtherVehicles Allows Copying Records from Any User's Vehicle Without Ownership Check

Published Sep 18, 2026
·
Updated

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecordsToOtherVehicles endpoint while naming destination vehicleIds the user could edit. The endpoint authorized the destination vehicles but fetched source records in Controllers/VehicleController.cs without checking UserCanEditVehicle for each existingRecord.VehicleId. This missing source-vehicle authorization allowed service, collision, upgrade, fuel, tax, supply, note, odometer, reminder, plan, inspection, and equipment records belonging to another user to be copied into an attacker-controlled vehicle, exposing record contents and attachment paths and creating persistent copies. This issue is fixed in version 1.6.8.

Affected Software

1 affected component
LubeLogger<1.6.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade LubeLogger to a version that resolves this vulnerability.

    Fixed in 1.6.8
  2. Operational

    After upgrading to 1.6.8, review and remove any attacker-created duplicate vehicle records (service, collision, upgrade, fuel, tax, supply, note, odometer, reminder, plan, inspection, and equipment records) created via the DuplicateRecordsToOtherVehicles endpoint, and investigate whether attachment paths/record contents were exposed.

Event History

Sep 18, 2026
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated LubeLogger user who can edit at least one destination vehicle can exploit it. The attacker can supply record IDs for source records from vehicles they do not own or otherwise have permission to edit.

2

What information can be exposed or copied?

An attacker can copy service, collision, upgrade, fuel, tax, supply, note, odometer, reminder, plan, inspection, and equipment records into a vehicle they control. The copied data can expose record contents and attachment paths, and the copies persist in the attacker's destination vehicle.

3

Are deployments affected by default?

Affected versions prior to 1.6.8 are vulnerable when multiple users have authenticated access and an attacker can edit a vehicle. Exploitation does not require user interaction beyond the attacker's authenticated access.

4

What should be done if an upgrade cannot happen immediately?

The provided information identifies version 1.6.8 as the fix but does not specify a workaround. Until upgrading, restrict access to trusted users and review whether untrusted authenticated users can edit vehicles.

5

How can administrators assess possible impact?

Review record duplication activity for copies appearing in vehicles controlled by users who should not have access to the source vehicle records. Pay particular attention to copied records and attachment paths originating from vehicles owned by different users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203