Skip to content
Threat Feed
high advisory

Johnson Controls Airwall Hard-coded Credentials and Path Traversal Vulnerabilities

Johnson Controls Airwall versions 4.0.4 and earlier are affected by CVE-2026-64887 and CVE-2026-34492, allowing attackers to potentially decrypt sensitive data or perform arbitrary file reads.

Johnson Controls has disclosed two vulnerabilities affecting Airwall products up to and including version 4.0.4. The first, CVE-2026-64887, involves the use of hard-coded cryptographic keys within the application, which are consistent across all installations. This allows an attacker who obtains the key through code analysis or binary inspection to decrypt sensitive application data, configuration files, and database content. The second issue, CVE-2026-34492, is an arbitrary file read vulnerability caused by improper validation of user-supplied input in file system operations. Attackers can leverage path traversal sequences (e.g., ../ or encoded variations) to read sensitive files from the underlying server, including private keys and credential stores. These vulnerabilities pose a significant risk to critical infrastructure sectors, including manufacturing, energy, and transportation, as they could lead to full system compromise if exploited in tandem.

Impact

Successful exploitation of these vulnerabilities allows an attacker to gain unauthorized access to sensitive system information. By extracting private keys and credentials, an attacker could escalate privileges or pivot into internal networks. Given the deployment of these devices in critical infrastructure sectors, the compromise of Airwall appliances could result in significant operational disruption and data exfiltration.

Recommendation

  • Upgrade all instances of Johnson Controls Airwall to version 4.1.0 or later immediately to patch both CVE-2026-64887 and CVE-2026-34492.
  • Audit existing deployments for unauthorized access to configuration files and sensitive key stores.
  • Implement network segmentation and strictly restrict management access to these devices, ensuring they are not exposed to the public internet.
  • Consult the Johnson Controls Product Security Advisory JCI-PSA-2026-25 and JCI-PSA-2026-18 for detailed hardening steps and remediation guidance.

Immediate actions

Patch Airwall firmware to version 4.1.0 or later

IT Operations 72h

Mitigations

Isolate Airwall management interfaces from the public internet

immediate IT Operations

All affected versions