SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-34496

HIGH · CVSS 7.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

A vulnerability in Johnson Controls' victor Web prior to version 7.1 on Windows allows for improper access control, potentially enabling unauthorized actions within the application. Organizations using affected versions should prioritize this issue to mitigate risks associated with unauthorized access and potential exploitation. Immediate action is recommended for those managing security in environments utilizing victor Web.

CVE
CVE-2026-34496
Severity
HIGH
CVSS
7.1
EPSS
0.21%
Windows

Original NVD Description

Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.