CVE-2026-11804
Last modified
CVE-2026-11804 is a medium-severity vulnerability rated 5.2/10 on the CVSS scale. Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before 4.14.6, before 4.15.5..
Description
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before 4.14.6, before 4.15.5.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Tridium | Niagara Framework | < 4.14.6; < 4.15.5 |
| Tridium | Niagara Enterprise Security | < 4.14.6; < 4.15.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-11804?
How severe is CVE-2026-11804?
How do I fix CVE-2026-11804?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-11799UXSS in Focus for iOS / Klar Webkit navigation. This vulnera…7.5
- CVE-2026-1180A flaw was identified in Keycloak’s OpenID Connect Dynamic C…5.8
- CVE-2026-11800A flaw was found in Keycloak. This JWT algorithm confusion v…8.1
- CVE-2026-11801The WPAdverts – Classifieds Plugin plugin for WordPress is v…7.5
- CVE-2026-11802The FoodBook Lite - Online Food Ordering System plugin for W…5.3
- CVE-2026-11803A maliciously crafted PDF file, when parsed through certain …7.8
- CVE-2026-11805Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-11806IBM WebSphere Application Server - Liberty 17.0.0.3 through …7.5
- CVE-2026-11807A missing authorization vulnerability was found in the Event…9.6
- CVE-2026-11809The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.…3.7
- CVE-2026-1181Altium 365 workspace endpoints were configured with an overl…9
- CVE-2026-11810The UpdateHub firmware-update agent's probe handler (z_impl_…7.5
Are you affected by CVE-2026-11804?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
