IM
IronMonkey Threat Research

CVE-2026-11804 MEDIUM

Published: 2026-07-23 | Last Modified: 2026-07-23 | Status: Deferred

Description

Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before 4.14.6, before 4.15.5.

CVSS Metrics

Base Score: 5.2 (MEDIUM)

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N

Attack VectorADJACENT_NETWORK
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactLOW
Availability ImpactNONE

Source: [email protected]

Type: Secondary

Exploitability Score: 0.9

Impact Score: 4.2

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-280
Notification
Message here