Search/CVE-2026-27693
CVE — Medium

CVE-2026-27693

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper escaping. An attacker with low privileges can create a device with a crafted name that injects XML content into exported files. If another user exports and opens the affected KML or GPX file, this can corrupt the file structure and spoof exported location data. This issue is fixed in version 6.13.0.

CVSS v3.1
5.4 MEDIUM
EPSS
0.18%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
ScopeCHANGED
ConfidentialityNONE
IntegrityLOW
AvailabilityLOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L
Connections
2 relationships
Timeline
disclosure → media coverage
May 5, 2026
Disclosure — published as a CVE record. · last revised by NVD May 8, 2026