{"id":"CVE-2026-52852","title":"Traccar is an open source GPS tracking system","summary":"Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report for a device in tha…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-674"],"vendor":"traccar","product":"traccar","affected":["traccar < 6.14.0"],"published":"2026-09-17","updated":"2026-09-21","sourceUpdated":"2026-09-21T21:17:04.167","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-52852","references":[{"url":"https://github.com/traccar/traccar/commit/8f6f59ac29d8b1222254e938672a0d99098fd800","label":"security-advisories@github.com"},{"url":"https://github.com/traccar/traccar/releases/tag/v6.14.0","label":"security-advisories@github.com"},{"url":"https://github.com/traccar/traccar/security/advisories/GHSA-6qh3-234v-r254","label":"security-advisories@github.com"},{"url":"https://github.com/traccar/traccar/security/advisories/GHSA-6qh3-234v-r254","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-21T21:06:43.641548Z"},"epss":0.00295,"epssPercentile":0.22323,"ingestedAt":"2026-09-17T19:26:25.316Z","slug":"CVE-2026-52852","body":"## Overview\n\nTraccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report for a device in that hierarchy. org.traccar.api.resource.GroupResource permits the parent cycle, while org.traccar.helper.model.AttributeUtil.lookup follows group parents without cycle detection, a visited set, or a depth limit. The storage-backed lookup reached through TripsConfig. and ReportUtils.slowTripsAndStops never terminates, pins a Jetty worker at high CPU after the client disconnects, and can exhaust the web/API worker pool when requests are repeated. The position-ingestion cache-backed path is not part of the confirmed affected scope. This issue is fixed in 6.14.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":208809,"id":"CVE-2026-52852","ts":1790027671273,"field":"exploit_available","old":"false","new":"true"}]}