---
id: CVE-2026-13742
title: >-
  Honeywell IQ MultiAccess, all versions prior to and including version 28,
  contain an improper digital signature verification vulnerability
summary: >-
  Honeywell IQ MultiAccess, all versions prior to and including version 28,
  contain an improper digital signature verification vulnerability. An attacker
  could potentially exploit this vulnerability, leading to the replacement of
  downloade…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-367
vendor: Honeywell Technologies
product: IQ MultiAccess
affected:
  - iq_multiaccess >= IQ.v27 <= 28
published: '2026-06-29'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T07:16:45.780'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13742'
references:
  - url: 'https://www.honeywell.com/us/en/product-security'
    label: psirt@honeywell.com
  - url: 'http://seclists.org/fulldisclosure/2026/Sep/88'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-06-29T16:24:12.302631Z'
cvssSource: cna
epss: 0.00115
epssPercentile: 0.01406
ingestedAt: '2026-09-27T06:43:46.835Z'
---

## Overview

Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verification vulnerability. An attacker could potentially exploit this vulnerability, leading to the replacement of downloaded file with a malicious one. Honeywell also recommends updating to the most recent version of this product, service, or offering [V27 SP1, V28 SP1]

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
