Description
Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233.

This issue affects victor Web: before 7.1.
Published: 2026-07-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CWE-269 describes a privilege escalation flaw that allows an attacker to elevate privileges within Johnson Controls victor Web for Windows. The vulnerability is referenced as capec-233, indicating that an attacker can obtain higher privileges than intended by exploiting a weakness in how the application handles user roles or access controls. The flaw exists in all pre‑7.1 releases of victor Web, enabling a threat actor who has local access to the system to gain administrative or equivalent rights, thereby compromising confidentiality, integrity, and availability of the affected environment.

Affected Systems

All installations of Johnson Controls victor Web running on Windows with a version earlier than 7.1 are affected. The product is not impacted if the system has been upgraded to 7.1 or later. No other vendor or product is listed in the CNA data.

Risk and Exploitability

The CVSS score of 7.1 reflects moderate severity, while the EPSS score of less than 1% indicates a low probability of real‑world exploitation. The vulnerability is not in CISA’s KEV catalog. Based on the description, the likely attack vector is local; an attacker needs to compromise a user account or execute code on the host to take advantage of the privilege escalation flaw. Without an explicit remote exploitation path, the risk is confined to environments where local access can be achieved, highlighting the importance of secure local configurations and restricted user privileges.

Generated by OpenCVE AI on August 3, 2026 at 20:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade victor Web to version 7.1 or later
  • Enforce the principle of least privilege on all local user accounts to limit potential damage from a compromised account
  • Configure and enable audit logging for changes to user roles and permissions to detect and respond to unauthorized privilege changes promptly

Generated by OpenCVE AI on August 3, 2026 at 20:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Johnsoncontrols
Johnsoncontrols victor Web
Vendors & Products Johnsoncontrols
Johnsoncontrols victor Web

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.
Title victor Web - Priviledge Escalation
First Time appeared Johnson Controls
Johnson Controls victor Web
CPEs cpe:2.3:a:johnson_controls:victor_web:*:*:windows:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls victor Web
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L'}


Subscriptions

Johnson Controls Victor Web
Johnsoncontrols Victor Web
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-07-24T13:36:00.484Z

Reserved: 2026-03-30T08:25:11.763Z

Link: CVE-2026-34496

cve-icon Vulnrichment

Updated: 2026-07-24T13:35:57.198Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-23T21:17:03.947

Modified: 2026-07-30T14:15:31.167

Link: CVE-2026-34496

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management