CVE-2026-78885 | liketrek TREK up to 3.0.22 OIDC Service oidcService.ts findOrCreateUser improper authentication (GHSA-fvgw-r58q-4cw4)

SecurityVulns

A vulnerability classified as problematic was found in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC Service. Such manipulation leads to improper authentication.

This vulnerability is referenced as CVE-2026-78885. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More