Customer Knowledge Base

📢Niagara Framework "Privilege Escalation Vulnerability"

Tridium has identified a privilege escalation vulnerability within the Niagara Program Module (program-rt.jar) A Patch for Niagara 4.14u5 and 4.15u4 is available.

image-20260716-121042.png

“Please Update Your Niagara Software”
This Addresses A Program Module Vulnerability

Classification: Partner Advisory
Date: 16 July 2026
Priority: High
Audience: Forest Rock Partners, System Integrators, Service Engineers, Technical Support Teams

Source: Tridium Bulletin

Security Bulletin: SB 2026-Tridium-1

CVE: CVE-2026-11804

CVSS Score: 5.2 (Medium)


Overview

Tridium has identified a security vulnerability within the program-rt.jar component of specific Niagara Framework releases.

Partners operating or maintaining affected Niagara installations should review their deployed versions and apply the recommended patch as soon as practical, following their standard change management and customer notification procedures. In addition to applying the patch, Tridium recommends reviewing Niagara user accounts, restricting physical access, using secure remote-access methods such as VPNs, reviewing the Security Dashboard, and following the Niagara Hardening Guide. tri-Niagara4-Hardening-Guide-en-2025.pdf


Affected Products

The vulnerability affects the following Niagara releases:

Product

Affected Version

Niagara Framework®

4.14u5

Niagara Enterprise Security

4.14u5

Niagara Framework®

4.15u4

Niagara Enterprise Security

4.15u4

Versions listed are based on Tridium Security Bulletin SB 2026-Tridium-1. This advisory applies to Niagara 4.14u5 and 4.15u4 systems.


Required Remediation

Tridium has issued updated versions of the program-rt.jar module:

Niagara Version

Replacement Module

4.14u5

program-rt-4.14.5.22.1.jar

4.15u4

program-rt-4.15.4.24.1.jar

Partners should install the appropriate replacement JAR file corresponding to the Niagara version deployed on site.


Patch Availability

The updated JAR files have been made available via our Document Download Site:

File: Programme Module Patches

Contained files:

  • program-rt-4.14.5.22.1.jar

  • program-rt-4.15.4.24.1.jar

    image-20260716-114933.png

The patch can typically be applied with minimal disruption.

Before You Begin

  • Locate the existing program-rt.jar file on the host system.  

    • This will be in the modules directory of your Niagara install, typically:

      • C:\Niagara\Niagara-4.14.x\modules

      • Or

      • C:\Niagara\Niagara-4.15.x\modules

  • Verify the Niagara version installed on the target system.

  • Confirm which patch file is required.

  • Inform the customer and obtain any required maintenance approval.

  • Schedule an appropriate maintenance window if the station serves a live production environment.

  • Ensure recent station, platform and licence backups are available before proceeding.

Installation Steps

  1. Stop all running Niagara stations.

  2. Close Niagara Workbench.

  3. Locate the existing program-rt.jar file on the host system.

  4. Replace the existing file with the patched version supplied by Tridium.

  5. Restart Niagara services and stations.

  6. Confirm successful station operation.

  7. Review station logs for any unexpected errors or warnings.


Validation

After applying the patch:

  • Confirm stations start normally.

  • Verify alarms, schedules, histories, and integrations continue to operate correctly.

  • Check the Platform and Application Director for any module loading errors.

  • Monitor the system for a suitable period following the upgrade.


Impact Assessment

This remediation is limited to replacement of the affected program-rt.jar module and does not require a full Niagara version upgrade.

Where standard change control processes are in place, the update should be treated as a security patch and managed accordingly.


Action Required

âś… Check all Niagara deployments for versions 4.14u5 and 4.15u4.
âś… Schedule patch implementation where affected versions are identified.
âś… Follow customer notification and maintenance procedures before applying changes.
âś… Validate system operation following installation.


For further assistance, please contact Forest Rock Technical Support.

PLEASE NOTE: Alternatively, customers planning routine maintenance may choose to upgrade to Niagara 4.14u6 or 4.15u5, which already contain this security fix.
Contact Technical Support for access to the latest files

Other Resources & Customer Survey:

đź’¬ Don't miss out! Follow the Forest Rock News channel on WhatsApp Click Here!
💬 We’d also love your feedback! Please take a moment to complete our quick Customer Survey
It only takes a minute and helps us serve you better!

image-20260224-141120.png

IoT Devices for BMS, Automation & Smart Connectivity | Forest Rock