Uncontrolled Search Path Element Vulnerability in Johnson Controls AC2000
CVE-2026-21661

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
6 May 2026

What is CVE-2026-21661?

The Uncontrolled Search Path Element vulnerability in Johnson Controls AC2000 on Windows presents a risk by allowing attackers to manipulate and leverage configuration file search paths, potentially leading to unauthorized access or execution of malicious code. This vulnerability affects versions 10.6 and earlier, 11.0 and earlier, and 12 and earlier of the AC2000 product. Users are advised to review their configurations and apply security measures to mitigate potential threats.

Affected Version(s)

AC2000 Windows 10.6

AC2000 Windows 11.0

AC2000 Windows 12

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.