CWE-269 Vulnerability in Johnson Controls Victor Web on Windows
CVE-2026-34496

7.1HIGH

Key Information:

Vendor
CVE Published:
23 July 2026

What is CVE-2026-34496?

A CWE-269 vulnerability has been identified in Johnson Controls' Victor Web software running on Windows. This security issue allows users with limited privileges to gain unauthorized access and execute malicious commands, which can compromise the integrity and confidentiality of the application. The vulnerability affects Victor Web versions prior to 7.1, highlighting the necessity for users to update their software to the latest version to mitigate potential security risks.

Affected Version(s)

victor Web Windows 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.