← All Advisories

Johnson Controls ADVMS Embeds a Hard-Coded Cryptographic Key, Exposing Sensitive Key Material to Local Low-Privilege Users on Versions Before 3.10

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-34499

Key Details

CVECVE-2026-34499
CVSS Score / Version8.5 (High) / CVSS v4.0
Updated2026-10-08
Affected productsJohnson Controls ADVMS
Classified asCWE-321 (Use of Hard-coded Cryptographic Key)
Exploitation prediction (EPSS)0.10% probability of exploitation in the next 30 days (1% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Johnson ControlsADVMS
SubsystemsGeneral OT
SectorsMultiple

What to Know

Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS allows Read Sensitive Constants Within an Executable.

This issue affects ADVMS: before 3.10. (NVD)

What to Do

Monitor Johnson Controls's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-34499
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-34499