Trane Tracer SC Products Missing Authorization Vulnerability Allowing Unauthenticated Access to Sensitive Information

Vulnerability

A missing authorization vulnerability exists in Trane Tracer SC, Tracer SC+, and Tracer Concierge. This vulnerability could enable an unauthenticated attacker to access sensitive information through unprotected APIs.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information.

Added: Mar 12, 2026, 6:25 PM
Updated: Mar 12, 2026, 6:25 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
7.0
remediation
0.0
relevance
3.9
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.