OS Command Injection in Johnson Controls Illustra Standard - L4L China
CVE-2026-34498

5.1MEDIUM

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-34498?

An improper input validation issue in Johnson Controls' Illustra Standard - L4L China software running on Windows allows for OS Command Injection. This vulnerability could enable an attacker to execute arbitrary commands within the operating system context, potentially compromising system integrity and confidentiality. Affected users are urged to update to version 6.0.0.66394 or later to mitigate risks associated with this vulnerability.

Affected Version(s)

Illustra Standard - L4L China Windows 0 < 6.0.0.66394

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.