HarborGuard / CVE
Back to search
HIGHCVE-2026-40185Published Modified CNA GitHub_M

CVE-2026-40185: Missing Authorization on Immich Trip Photo Routes in TREK

TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo management routes. This vulnerability is fixed in 2.7.2.

Metrics

CVSS v3.1
7.1
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • mauriceboe / TREK
    < 2.7.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVE-2026-40185: Missing Authorization on Immich Trip Photo Routes in TREK | HarborGuard CVE