honeywellCVE-2026-11804
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows...
Medium5.2CVE-2026-11804 · Published Jul 23, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Niagara Enterprise Security Vendor | < 4.14.6 | 4.14.6 |
| < 4.15.5 | 4.15.5 | |
| Niagara Framework Vendor | < 4.14.6 | 4.14.6 |
| < 4.15.5 | 4.15.5 |
Details and references
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before 4.14.6, before 4.15.5.
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
- Severity from
- no source yet
- Weakness
- CWE-280
More honeywell advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 27 | Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14. CVE-2026-17612Medium6.9no fix yet | Medium6.9 | No fix yet |
| Sep 24 | An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer... CVE-2026-13248High8.8fixed in PD45 Industrial Printer F10.22.030745 | High8.8 | PD45 Industrial Printer F10.22.030745 |
| Sep 24 | An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19. CVE-2026-13249Critical9.8fixed in PD45 Industrial Printer F10.22.030745 | Critical9.8 | PD45 Industrial Printer F10.22.030745 |