Home

Description

A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.

PUBLISHED Reserved 2026-02-25 | Published 2026-03-12 | Updated 2026-03-12 | Assigner icscert




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

Any version before v4.4 SP7
affected

Default status
unaffected

Any version before v6.3.2310
affected

Default status
unaffected

Any version before v6.3.2310
affected

Credits

Noam Moshe of Claroty reported these vulnerabilities to CISA. finder

References

www.cisa.gov/news-events/ics-advisories/icsa-26-071-01 government-resource

cve.org (CVE-2026-28254)

nvd.nist.gov (CVE-2026-28254)

Download JSON