A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Trane has released the following versions of Tracer SC+ for users to upgrade to: * CVE-2026-28254: Tracer SC+ version v6.30.2313
Workaround
No workaround given by the vendor.
References
History
Thu, 12 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs. | |
| Title | Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-03-12T17:29:56.723Z
Reserved: 2026-02-25T17:06:34.954Z
Link: CVE-2026-28254
No data.
Status : Received
Published: 2026-03-12T18:16:23.547
Modified: 2026-03-12T18:16:23.547
Link: CVE-2026-28254
No data.
OpenCVE Enrichment
No data.
Weaknesses