CVE-2026-21661: AC2000 Uncontrolled Search Path Element
An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths.
This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JohnsonControls AC2000to a version that resolves this vulnerability.Fixed in 10.6 - Upgrade
Upgrade
JohnsonControls AC2000to a version that resolves this vulnerability.Fixed in 11.0 - Upgrade
Upgrade
JohnsonControls AC2000to a version that resolves this vulnerability.Fixed in 12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21661?
CVE-2026-21661 has a moderate severity level due to its potential to allow manipulation of configuration paths.
How do I fix CVE-2026-21661?
To fix CVE-2026-21661, update Johnson Controls AC2000 to a version that is beyond the specified vulnerable release thresholds.
What versions of AC2000 are affected by CVE-2026-21661?
CVE-2026-21661 affects AC2000 versions from 10.6 before release 10, from 11.0 before release 9, and from 12 before release 3.
What impact does CVE-2026-21661 have on AC2000 users?
The impact of CVE-2026-21661 allows unauthorized leveraging or manipulation of configuration file search paths, potentially leading to system compromise.
Is CVE-2026-21661 being actively exploited?
As of now, there are no publicly reported exploits for CVE-2026-21661, but users are still advised to mitigate the risk by updating their software.