logo

CVE-2026-45410 | mauriceboe TREK up to 3.0.17 Email Address information exposure (GHSA-3552-3c98-x79r)

ID: 4ca92ed6-fe4d-5472-9718-2023adfbd1b2

STIX ID: report--4ca92ed6-fe4d-5472-9718-2023adfbd1b2

Feed Name: VulDB Recent Entries

Threat Score
35/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: vuldb.com

...
...

CVE-2026-45410 is a timing-based user enumeration vulnerability in TREK up to 3.0.17 where the backend's bcrypt password comparison introduces a ~370 ms delay when a supplied email exists versus ~10 ms when it does not, enabling remote, unauthenticated attackers to distinguish valid accounts; the issue is rated medium (VulDB ~5.2) and fixed in TREK 3.0.18 with no public exploit reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.