Sploitus

CVE-2026-27644

No indexed exploits for CVE-2026-27644 yet

Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can inject spreadsheet formulas through exported fields. When a manager or administrator opens the exported CSV file in spreadsheet software, this can cause formula execution and lead to command execution or data exfiltration. This has been patched in version 6.13.0.

Affected products
Traccar
Traccar
< 6.13.0
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.2% (14th percentile)
Weakness
CWE-1236
NVD status
Analyzed
Published
2026-05-05
CVE-2026-27644 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-27644 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-27644 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.