CVE-2026-28254

A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:trane:tracer_sc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack1:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack2:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack3:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack4:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack5:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack6:*:*:*:*:*:*
cpe:2.3:h:trane:tracer_sc:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:trane:tracer_sc\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:trane:tracer_sc\+:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:trane:tracer_concierge:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-12 18:16

Updated : 2026-03-27 16:24


NVD link : CVE-2026-28254

Mitre link : CVE-2026-28254

CVE.ORG link : CVE-2026-28254


JSON object : View

Products Affected

trane

  • tracer_concierge
  • tracer_sc\+
  • tracer_sc\+_firmware
  • tracer_sc
  • tracer_sc_firmware
CWE
CWE-862

Missing Authorization