Loading
A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
Use CWE-862, Trane vendor hub and Tracer Sc Firmware product page to widen CVE-2026-28254 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-38450, CVE-2026-28252 and CVE-2026-28253 for nearby disclosures in the same product family.