CVE-2026-78863 | liketrek TREK up to 3.0.22 Pre-2FA mfa_token authService.ts loginUser improper authentication (GHSA-mjh4-w6fq-54qm)

SecurityVulns

A vulnerability described as critical has been identified in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. The manipulation results in improper authentication.

This vulnerability was named CVE-2026-78863. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More