CVE-2026-27694

Source
https://cve.org/CVERecord?id=CVE-2026-27694
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27694.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-27694
Aliases
  • GHSA-6hfr-mj4m-hrvv
Published
2026-05-05T12:20:55.174Z
Modified
2026-07-15T01:49:08.316706487Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
traccar allows stored HTML injection in notification emails
Details

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geofence, and driver names into HTML email output without proper escaping. An attacker with low privileges can store crafted HTML in these fields, which is then rendered in notification emails sent to other users with access to the affected devices. This can lead to phishing or spoofed email content. This issue is fixed in version 6.13.0.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27694.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/traccar/traccar

Affected ranges

Type
GIT
Repo
https://github.com/traccar/traccar
Events
Database specific
{
    "cpe": "cpe:2.3:a:traccar:traccar:*:*:*:*:*:*:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "6.11.1"
        },
        {
            "fixed": "6.13.0"
        }
    ]
}

Affected versions

v6.*
v6.11.1
v6.12.0
v6.12.1
v6.12.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27694.json"