This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 06 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3. | |
| Title | AC2000 Uncontrolled Search Path Element | |
| First Time appeared |
Johnsoncontrols
Johnsoncontrols ac2000 |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:johnsoncontrols:ac2000:*:*:windows:*:*:*:*:* | |
| Vendors & Products |
Johnsoncontrols
Johnsoncontrols ac2000 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: jci
Published:
Updated: 2026-05-06T19:02:28.291Z
Reserved: 2026-01-02T13:23:28.170Z
Link: CVE-2026-21661
Updated: 2026-05-06T19:02:23.363Z
Status : Awaiting Analysis
Published: 2026-05-06T17:16:21.890
Modified: 2026-05-06T19:05:56.337
Link: CVE-2026-21661
No data.
OpenCVE Enrichment
Updated: 2026-05-06T23:45:06Z