SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-64896

MEDIUM · CVSS 5.2 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Johnson Controls T2000 system prior to version 31.6 contains a vulnerability in its debug and test interface that allows unauthorized access to functionalities due to improper access control mechanisms. This could lead to potential exploitation by attackers to manipulate system operations or access sensitive data. Organizations using affected versions of the T2000 should prioritize patching to mitigate the risk associated with this vulnerability.

CVE
CVE-2026-64896
Severity
MEDIUM
CVSS
5.2
EPSS
0.15%

Original NVD Description

Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6.