---
id: CVE-2026-78863
title: A vulnerability was found in liketrek TREK up to 3.0.22
summary: >-
  A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the
  function loginUser of the file server/src/services/authService.ts of the
  component Pre-2FA mfa_token Handler. The manipulation results in improper
  authentication. T…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-287
published: '2026-08-25'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T23:10:00.143'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78863'
references:
  - url: 'https://github.com/liketrek/TREK/releases/tag/v3.1.0'
    label: cna@vuldb.com
  - url: 'https://github.com/mauriceboe/TREK/security/advisories/GHSA-mjh4-w6fq-54qm'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-78863'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/886929'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/394939'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/394939/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-09-28T23:23:00.550Z'
---

## Overview

A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. The manipulation results in improper authentication. The attack may be performed from remote. Upgrading to version 3.1.0 is recommended to address this issue. Upgrading the affected component is recommended.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
