CVE-2026-34498

Summary

Improper input validation vulnerability in Johnson Controls Illustra Standard - L4L China on Windows allows OS Command Injection.

This issue affects Illustra Standard - L4L China: before 6.0.0.66394.

Affected Software

VendorProductVersion RangeStatus
Johnson ControlsIllustra Standard - L4L China0 < 6.0.0.66394affected

Weaknesses

  • CWE-20: CWE-20 Improper input validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References