CVE-2026-40185 - Missing Authorization on Immich Trip Photo Routes in TREK
CVE ID :CVE-2026-40185
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization che...
Related Vulnerabilities
- CVE-2026-35669: OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plu HIGH
- CVE-2026-5144: The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions HIGH
- CVE-2026-5412: In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. CRITICAL
- CVE-2026-40189: goshs has a file-based ACL authorization bypass in goshs state-changing routes CRITICAL
- CVE-2026-1924: The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers MEDIUM
Related Coverage
Threat Actors