Improper Privilege Management in Johnson Controls Easy IO FG
CVE-2026-27872

5.6MEDIUM

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-27872?

The vulnerability in Johnson Controls Easy IO FG involves improper privilege management, enabling attackers to exploit this flaw via brute force methods. This issue is present in versions prior to 2.0b52, potentially allowing unauthorized access to system functionalities. Organizations utilizing affected versions should take remedial actions as outlined in the security advisory.

Affected Version(s)

Easy IO FG 0 < 2.0b52

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Gardois
.