CVE-2026-78885: liketrek TREK OIDC Service oidcService.ts findOrCreateUser improper authentication
A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC Service. Such manipulation leads to improper authentication. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. Upgrading to version 3.1.0 is sufficient to resolve this issue. Upgrading the affected component is advised.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
liketrek TREK OIDC Service (file server/src/services/oidcService.ts, function findOrCreateUser)to a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
Which TREK deployments are affected?
liketrek TREK versions up to and including 3.0.22 are affected in the OIDC Service component, specifically its server/src/services/oidcService.ts findOrCreateUser function.
Can this be exploited remotely, and does an attacker need an account?
The attack can be launched remotely and the published vector indicates no privileges or user interaction are required. Exploitation has high complexity and is regarded as difficult.
What is the recommended remediation?
Upgrade TREK to version 3.1.0. The available information states that this version is sufficient to resolve the issue.