Back to overview

CVE-2026-48745

CRITICAL
9.3
CVSS 3.1
Description
Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a custom org.traccar.client://config deep-link scheme that silently writes attacker-supplied parameters (server URL, device ID, accuracy, distance, and interval) into the app's persistent configuration with no confirmation, notification, or visual indication. A single crafted link delivered via SMS, email, a webpage, or any installed app can therefore reconfigure the app the moment the victim taps it, with no special permissions required. As a result, an attacker can covertly redirect all of the victim's GPS telemetry to their own server at maximum precision and frequency, and the change persists across restarts. This gives the attacker continuous, real-time tracking of the victim's location. This issue has been fixed in version 9.7.20.

Metadata

CVE ID
CVE-2026-48745
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-05-22 19:10 UTC
Published
2026-06-16 22:19 UTC
Last updated
2026-06-17 13:53 UTC
Primary CWE
CWE-940
CWE-940: Improper Verification of Source of a Communication …
Vendor / Product
traccar / traccar-client
Sources
cve.org  ·  NVD

Severity & Metrics

9.3 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
traccar traccar-client < 9.7.20
Weakness (CWE)
CWESourceDescription
CWE-940 cna CWE-940: Improper Verification of Source of a Communication Channel
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.3 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
References (2)
Back to overview