CVE-2026-27872

N/A

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are a...

Affects 0 products across 1 vendor.

CVSS v45.6
EPSS0.1%
Percentile0th
PatchUnknown
CWE Weakness Definitions
CWE-269: Improper Privilege Management

Software does not properly assign, modify, track, or check privileges, allowing unauthorized elevation of access.

Related Attack Patterns (CAPEC)
CAPEC-58 Restful Privilege Elevation
via CWE-269
CAPEC-122 Privilege Abuse
via CWE-269
CAPEC-233 Privilege Escalation
via CWE-269

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A unscored severity vulnerability (CVE-2026-27872) affects the target system. - Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-27872?
A unscored severity vulnerability (CVE-2026-27872) affects the target system. - Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.
Is CVE-2026-27872 actively exploited?
No confirmed active exploitation of CVE-2026-27872 as of 2026-10-08.
How do I remediate CVE-2026-27872?
Apply vendor patches for CVE-2026-27872. Monitor Johnsoncontrols advisories.
What systems are affected by CVE-2026-27872?
CVE-2026-27872 affects: Johnsoncontrols.
Vulnerability Details
CVE IDCVE-2026-27872
Published2026-10-01
Last Modified2026-10-06
ICS Relevance70%
Weakness (CWE)
SourceNVD
Official Description

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873) CVSS Vendor Equipment v3 7.7 Johnson Controls EasyIO FG firmware 2 Vulnerabilities Use of Hard-coded Credentials, Improper Privilege Management Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductAffected Versions
Johnsoncontrols &mdash; —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 6 Days
CISA known-exploitedNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Johnsoncontrols
CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2... CVE-2014-5428 10.0 Unrestricted file upload vulnerability in unspecified web services in Johnson... CVE-2021-27664 9.8 Under certain configurations an unauthenticated remote user could be given ac... CVE-2019-7589 9.8 A vulnerability with the SmartService API Service option exists whereby an un... CVE-2021-27663 9.8 A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems...
View all Johnsoncontrols CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.

Create a free account →