CVE-2026-11804
MEDIUM
5.2
CVSS 3.1
Description
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse.
This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before 4.14.6, before 4.15.5.
Metadata
Severity & Metrics
5.2
MEDIUM CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
SSVC — CISA Coordinator
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Tridium | Niagara Enterprise Security | Windows,Linux,QNX | 0 < 4.14.6, 0 < 4.15.5 |
| Tridium | Niagara Framework | Windows,Linux,QNX | 0 < 4.14.6, 0 < 4.15.5 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-280 | cna | CWE-280 Improper handling of insufficient permissions or privileges |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.2 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N |
References (2)