A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.

Project Subscriptions

Vendors Products
Tracer Concierge Subscribe
Tracer Sc Subscribe
Advisories

No advisories yet.

Fixes

Solution

Trane has released the following versions of Tracer SC+ for users to upgrade to: * CVE-2026-28254: Tracer SC+ version v6.30.2313


Workaround

No workaround given by the vendor.

History

Fri, 13 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Trane
Trane tracer Concierge
Trane tracer Sc
Vendors & Products Trane
Trane tracer Concierge
Trane tracer Sc

Thu, 12 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 17:45:00 +0000

Type Values Removed Values Added
Description A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
Title Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-03-12T19:21:04.760Z

Reserved: 2026-02-25T17:06:34.954Z

Link: CVE-2026-28254

cve-icon Vulnrichment

Updated: 2026-03-12T19:20:39.349Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-12T18:16:23.547

Modified: 2026-03-12T21:07:53.427

Link: CVE-2026-28254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-13T09:50:46Z

Weaknesses