A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Trane has released the following versions of Tracer SC+ for users to upgrade to: * CVE-2026-28255: Trane has implemented enhanced cloud security controls to mitigate this vulnerability.


Workaround

No workaround given by the vendor.

History

Thu, 12 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 18:00:00 +0000

Type Values Removed Values Added
Description A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
Title Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
Weaknesses CWE-547
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-03-12T18:00:32.808Z

Reserved: 2026-02-25T17:06:34.954Z

Link: CVE-2026-28256

cve-icon Vulnrichment

Updated: 2026-03-12T18:00:26.773Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-12T18:16:23.917

Modified: 2026-03-12T21:07:53.427

Link: CVE-2026-28256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses