CVE-2026-34499: High severity Johnson Controls ADVMS vulnerability
Published Oct 7, 2026
·Updated
Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS allows Read Sensitive Constants Within an Executable.
This issue affects ADVMS: before 3.10.
Affected Software
1 affected component
Johnson Controls ADVMS<3.10
Event History
Oct 7, 2026
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Johnson Controls ADVMS versions before 3.10 are affected.
2
What level of access does an attacker need?
The CVSS vector indicates local access and low privileges are required. No user interaction or additional attack conditions are required.
3
What is the impact of successful exploitation?
An attacker can read sensitive constants within an executable. The CVSS assessment indicates high impact to confidentiality, integrity, and availability, including subsequent-system impacts.