CVE-2026-62945 | liketrek TREK up to 3.1.2 File Linking link findForeignLinkTarget reservation_id/place_id/assignment_id authorization
A vulnerability identified as problematic has been detected in liketrek TREK up to 3.1.2. Affected is the function findForeignLinkTarget of the file /api/trips/:tripId/files/:id/link of the component File Linking. This manipulation of the argument reservation_id/place_id/assignment_id causes authorization bypass.
This vulnerability is tracked as CVE-2026-62945. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.VulDB Recent EntriesRead More