
CVE-2026-28254 A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information thr… https://www.cve.org/CVERecord?id=CVE-2026-28254
Post summary
The post announces the disclosure of CVE-2026-28254, a missing authorization flaw in Trane Tracer devices that permits unauthenticated access to sensitive data.
