CVE-2026-34492
7.0Johnson Controls · Airwall
Johnson Controls Airwall is susceptible to an external control of file name or path vulnerability, potentially allowing unauthorized file manipulation.
Executive summary
A file path manipulation vulnerability in Johnson Controls Airwall could allow remote, unauthenticated attackers to perform unauthorized file operations.
Vulnerability
This vulnerability involves the external control of file names or paths (CWE-73). It allows an attacker to influence which files the application accesses or modifies, potentially leading to unauthorized system state changes despite the requirement for user interaction.
Business impact
The vulnerability carries a CVSS score of 7.0, indicating high severity. Successful exploitation could result in unauthorized file manipulation, which may compromise system integrity, lead to the disclosure of sensitive information, or disrupt the operation of the Airwall security infrastructure.
Remediation
Immediate Action: Update Johnson Controls Airwall to version 4.1 or later to remediate the file path manipulation flaw.
Proactive Monitoring: Monitor system logs for attempts to access or modify files outside of expected directories, and review audit logs for anomalous administrative actions.
Compensating Controls: Utilize a Web Application Firewall or similar filtering mechanism to inspect and sanitize incoming requests for path traversal or malicious file path patterns.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the critical nature of security infrastructure like Airwall, organizations must prioritize upgrading to the latest version. Patching is the only reliable method to mitigate the risk of unauthorized file system interaction in this product.