Program Module Vulnerability
Summary
| CVE | CVE-2026-11804 |
|---|---|
| State | PUBLISHED |
| Assigner | Honeywell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-23 16:17:13 UTC |
| Updated | 2026-07-23 19:16:51 UTC |
| Description | Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before 4.14.6, before 4.15.5. |
Risk And Classification
Primary CVSS: v3.1 5.2 MEDIUM from [email protected]
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Problem Types: CWE-280 | CWE-280 CWE-280 Improper handling of insufficient permissions or privileges
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.2 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N |
| 3.1 | CNA | CVSS | 5.2 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
LowAvailability
NoneCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Tridium | Niagara Framework | affected 4.14.6 custom | Windows, Linux, QNX |
| CNA | Tridium | Niagara Framework | affected 4.15.5 custom | Windows, Linux, QNX |
| CNA | Tridium | Niagara Enterprise Security | affected 4.14.6 custom | Windows, Linux, QNX |
| CNA | Tridium | Niagara Enterprise Security | affected 4.15.5 custom | Windows, Linux, QNX |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.honeywell.com/us/en/product-security | [email protected] | www.honeywell.com | |
| www.tridium.com/us/en/product-security | [email protected] | www.tridium.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Umut Pirkoca (en)
Additional Advisory Data
Solutions
CNA: Tridium recommends upgrading to one of the following versions: * Niagara Framework 4.14u6 * Niagara Enterprise Security 4.14u6 * Niagara Framework 4.15u5 * Niagara Enterprise Security 4.15u5 or applying the following patched modules * program-rt.jar version 4.14.5.22.1 * program-rt.jar version 4.15.4.24.1
There are currently no legacy QID mappings associated with this CVE.