Executive brief
Johnson Controls CEM AC2000 is an access control and security management system used in critical infrastructure environments. A vulnerability in this software allows a user with low-level access to the host computer to gain full administrative control. This could lead to unauthorized access to sensitive security data, disruption of facility operations, or the ability to bypass physical security measures.
Technical details
The vulnerability is classified as an Uncontrolled Search Path Element (CWE-427), specifically manifesting as a DLL hijacking flaw. It resides in the CEM AC2000 software versions 10.6, 11.0, and 12.0. An attacker with local access and standard user privileges can place a malicious DLL in a location searched by the application, which is then executed with higher privileges. Successful exploitation allows for a full privilege escalation on the host machine. Johnson Controls has released updates (10.6 Release 3, 11.0 Release 9, and 12.0 Release 10) to remediate this issue.
Affected products
- Johnson Controls Inc. CEM AC2000 10.6, 11.0, 12.0
Timeline
- 2026-05-05: disclosed
- 2026-05-05: advisory