Junglewise Threat Intelligence

CVE-2026-34496: Johnson Controls victor Web privilege escalation on Windows

CVE-2026-34496 · Severity: info · CVSS 7.1 · Published 2026-07-23

Vendors: Johnson Controls.

Executive brief

A privilege escalation vulnerability exists in Johnson Controls victor Web, a video management solution used for security and surveillance operations. An attacker with high-level administrative access could exploit this flaw to gain even greater control over the system, potentially compromising the integrity of security data or disrupting surveillance operations. This issue is resolved in version 7.1 and later.

Technical details

A privilege escalation vulnerability (CWE-269) exists in Johnson Controls victor Web on Windows prior to version 7.1. The flaw allows an attacker to perform an 'unauthorized delegation' (CAPEC-233), effectively gaining rights beyond their intended level. Exploitation requires high privileges (PR:H) and occurs over the network, though it is constrained by high attack complexity and specific technical preconditions. Successful exploitation can lead to a high impact on confidentiality and a low impact on the integrity and availability of the system. Users are advised to upgrade to version 7.1 or later.

Affected products

  • Johnson Controls victor Web before 7.1

Timeline

  • 2026-07-23: advisory: Initial advisory published by Johnson Controls and NVD.

References