CVE-2026-77293 | mauriceboe TREK up to 3.2.x Collab Service collabService.ts deleteNoteFile tripId/noteId/fileId improper authorization

SecurityVulns

A vulnerability classified as problematic was found in mauriceboe TREK up to 3.2.x. Affected is the function deleteNoteFile of the file server/src/services/collabService.ts of the component Collab Service. Executing a manipulation of the argument tripId/noteId/fileId can lead to improper authorization.

This vulnerability appears as CVE-2026-77293. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.VulDB Recent EntriesRead More