Improper Access Control in Johnson Controls T2000 Product
CVE-2026-64896

5.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-64896?

The T2000 product from Johnson Controls exhibits a vulnerability related to its Debug and Test Interface, allowing unauthorized access to functionalities that are not effectively restricted by Access Control Lists (ACLs). This issue compromises the integrity of system operations and could facilitate unauthorized actions if left unaddressed.

Affected Version(s)

T2000 0 < 31.6

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.