Junglewise Threat Intelligence

CVE-2026-78885: liketrek TREK OIDC authentication bypass

CVE-2026-78885 · Severity: medium · CVSS 5.6 · Published 2026-08-25

Technologies: Liketrek TREK. Vendors: Liketrek.

Executive brief

TREK is a self-hosted expense and trip-tracking application. The OIDC (single sign-on) login function fails to verify email addresses, allowing an attacker with access to a permissive identity provider to claim an existing user's email address and hijack their account permanently.

Technical details

The vulnerability exists in the findOrCreateUser function of server/src/services/oidcService.ts. When an OIDC identity provider logs in a user, the function matches incoming SSO identities to existing local accounts by comparing email addresses (case-insensitive) without verifying the email_verified claim from the provider. An attacker using an identity provider that does not enforce email verification can set their profile email to match a victim's email address; when they log in via OIDC, their identity is auto-linked to the victim's account, granting persistent account access. The attack requires network access and a permissive identity provider (high attack complexity). The fix, deployed in version 3.1.0, requires email_verified to be true before auto-linking to an existing account; otherwise login is rejected with an oidc_error.

Affected products

  • liketrek TREK up to 3.0.22

Timeline

  • 2026-06-16: disclosed: Fixed in v3.1.0 release
  • 2026-06-16: advisory: GHSA-fvgw-r58q-4cw4 published

References