CVE-2026-27872
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are a...
Affects 0 products across 1 vendor.
Software does not properly assign, modify, track, or check privileges, allowing unauthorized elevation of access.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A unscored severity vulnerability (CVE-2026-27872) affects the target system. - Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-27872?
Is CVE-2026-27872 actively exploited?
How do I remediate CVE-2026-27872?
What systems are affected by CVE-2026-27872?
| CVE ID | CVE-2026-27872 |
|---|---|
| Published | 2026-10-01 |
| Last Modified | 2026-10-06 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Source | NVD |
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873) CVSS Vendor Equipment v3 7.7 Johnson Controls EasyIO FG firmware 2 Vulnerabilities Use of Hard-coded Credentials, Improper Privilege Management Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities
Source: NIST NVD / MITRE CVE Database
| Vendor | Product | Affected Versions |
|---|---|---|
| Johnsoncontrols | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA known-exploited | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.
Create a free account →