Traccar through 6.16.0 contains a weak password recovery vulnerability that allows attackers to reuse password reset tokens as session credentials because TokenManager does not bind tokens to a purpose. Attackers holding a leaked reset link can obtain a full session via /api/session or change passwords via /api/password/update, retaining access for seven days even after the victim resets their password.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Traccar through 6.16.0 contains a weak password recovery vulnerability that allows attackers to reuse password reset tokens as session credentials because TokenManager does not bind tokens to a purpose. Attackers holding a leaked reset link can obtain a full session via /api/session or change passwords via /api/password/update, retaining access for seven days even after the victim resets their password.
Title Traccar through 6.16.0 Weak Password Recovery via TokenManager Token Purpose Confusion
First Time appeared Traccar
Traccar traccar
Weaknesses CWE-640
CPEs cpe:2.3:a:traccar:traccar:*:*:*:*:*:*:*:*
Vendors & Products Traccar
Traccar traccar
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:42.967Z

Reserved: 2026-10-11T01:52:49.949Z

Link: CVE-2026-108737

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T13:17:18.053

Modified: 2026-10-11T13:17:18.173

Link: CVE-2026-108737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses