CVE-2026-78863: liketrek TREK Pre-2FA mfa_token authService.ts loginUser improper authentication
A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfatoken Handler. The manipulation results in improper authentication. The attack may be performed from remote. Upgrading to version 3.1.0 is recommended to address this issue. Upgrading the affected component is recommended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
liketrek TREK Pre-2FA mfa_token Handler (authService.ts loginUser)to a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
Which deployments are affected?
liketrek TREK versions up to 3.0.22 are affected, specifically the Pre-2FA mfa_token handling in loginUser within server/src/services/authService.ts.
What access does an attacker need?
The issue can be exploited remotely and requires low privileges. No user interaction is required.
Is there a fixed version?
Upgrade liketrek TREK to version 3.1.0, which is the recommended version to address the issue.