CYBERSECURITYTRACKER
TRACKING
Permanent story citation

SEC Consult SA-20260923-0 :: Local Privilege Escalation in Honeywell IQ MultiAccess Update Service #CVE-2026-13742

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8660

As cited

Copy frozen at (site build).

vulnerabilities

SEC Consult SA-20260923-0 :: Local Privilege Escalation in Honeywell IQ MultiAccess Update Service #CVE-2026-13742

Honeywell IQ MultiAccess Update Service versions 27 and 28 contain a local privilege escalation vulnerability tracked as CVE-2026-13742. The vulnerability carries a high impact rating and has been fixed in service pack 1 releases for both affected versions.

Why it matters: Organizations running Honeywell IQ V27 or V28 must patch to SP1 immediately to prevent local attackers from escalating privileges on systems with this update service installed.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary