CVE-2026-28254
Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
| CWE | CWE-862 |
| Vendor | trane |
| Product | tracer sc |
| Published | Mar 12, 2026 |
| Last Updated | Mar 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for trane tracer sc
Be the first to know when new unknown vulnerabilities affecting trane tracer sc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Trane / Tracer SC
0 < v4.4 SP7
Trane / Tracer SC+
0 < v6.3.2310
Trane / Tracer Concierge
0 < v6.3.2310
References
Credits
Noam Moshe of Claroty reported these vulnerabilities to CISA.