← All Advisories

Johnson Controls AC2000 Access Control System Uncontrolled Search Path Allows Authenticated Local Attacker to Leverage Configuration File Paths

Last refreshed2026-10-07

Status: UPDATED  |  Advisory ID: CVE-2026-21661

Key Details

CVECVE-2026-21661
CVSS Score / Version8.4 (High) / CVSS v4.0
Updated2026-08-24
Affected productsJohnson Controls AC2000
Classified asCWE-427 (Uncontrolled Search Path Element)
Exploitation prediction (EPSS)0.11% probability of exploitation in the next 30 days (1% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Johnson ControlsAC2000
SubsystemsGeneral OT
SectorsMultiple

What to Know

An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths.

This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3. (NVD)

What to Do

Monitor Johnson Controls's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-21661
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-21661