CVE-2026-78885: liketrek TREK OIDC Service oidcService.ts findOrCreateUser improper authentication

Published Aug 25, 2026
·
Updated

A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC Service. Such manipulation leads to improper authentication. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. Upgrading to version 3.1.0 is sufficient to resolve this issue. Upgrading the affected component is advised.

Affected Software

2 affected components
liketrek/TREK/OIDC Service<=3.0.22
liketrek/TREK/OIDC Service>=undefined

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade liketrek TREK OIDC Service (file server/src/services/oidcService.ts, function findOrCreateUser) to a version that resolves this vulnerability.

    Fixed in 3.1.0

Event History

Aug 25, 2026
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which TREK deployments are affected?

liketrek TREK versions up to and including 3.0.22 are affected in the OIDC Service component, specifically its server/src/services/oidcService.ts findOrCreateUser function.

2

Can this be exploited remotely, and does an attacker need an account?

The attack can be launched remotely and the published vector indicates no privileges or user interaction are required. Exploitation has high complexity and is regarded as difficult.

3

What is the recommended remediation?

Upgrade TREK to version 3.1.0. The available information states that this version is sufficient to resolve the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203