This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before 4.14.6, before 4.15.5.
Project Subscriptions
No data.
No advisories yet.
Solution
Tridium recommends upgrading to one of the following versions: * Niagara Framework 4.14u6 * Niagara Enterprise Security 4.14u6 * Niagara Framework 4.15u5 * Niagara Enterprise Security 4.15u5 or applying the following patched modules * program-rt.jar version 4.14.5.22.1 * program-rt.jar version 4.15.4.24.1
Workaround
No workaround given by the vendor.
Thu, 23 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before 4.14.6, before 4.15.5. | |
| Title | Program Module Vulnerability | |
| Weaknesses | CWE-280 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Honeywell
Published:
Updated: 2026-07-23T15:07:42.043Z
Reserved: 2026-06-09T15:04:29.906Z
Link: CVE-2026-11804
No data.
No data.
No data.
OpenCVE Enrichment
No data.