Junglewise Threat Intelligence

CVE-2026-27875: Johnson Controls Simplex Incident Manager cleartext storage of sensitive information

CVE-2026-27875 · Severity: info · Published 2026-08-21

Vendors: Johnson Controls.

Executive brief

Johnson Controls Simplex Incident Manager / Autocall Fire Administrator is a fire management system used to administer and monitor fire suppression and detection infrastructure. A cleartext storage vulnerability allows an attacker with local access to memory to retrieve sensitive embedded data such as credentials or configuration secrets, potentially compromising fire safety operations.

Technical details

The vulnerability is a cleartext storage of sensitive information weakness in memory within Simplex Incident Manager / Autocall Fire Administrator versions before 2.01.05. The affected component stores sensitive data (credentials, API keys, or other secrets) unencrypted in process memory, allowing an attacker with local system access to read this information via memory inspection or dumps. The attack requires local access to the system; remote exploitation is not possible. An attacker could retrieve embedded sensitive data and use it to compromise the fire management system or related infrastructure. Patches are available in version 2.01.05 and later.

Affected products

  • Johnson Controls Simplex Incident Manager before 2.01.05
  • Johnson Controls Autocall Fire Administrator before 2.01.05

Timeline

  • 2026-08-21: disclosed

References