CVE-2026-108738 | Traccar 5.7/6.16.0 OpenID Connect Callback callback state cross-site request forgery
A vulnerability was found in Traccar 5.7/6.16.0. It has been classified as problematic. This impacts an unknown function of the file /api/session/openid/callback of the component OpenID Connect Callback. The manipulation of the argument state leads to cross-site request forgery.
This vulnerability is referenced as CVE-2026-108738. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More