CVE-2026-21659 PUBLISHED

Johnson Controls -Frick Quantum HD-Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion

Assigner: jci
Reserved: 02.01.2026 Published: 27.02.2026 Updated: 27.02.2026

Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthenticated attacker to execute arbitrary code on the affected device, leading to full system compromise. This issue affects Frick Controls Quantum HD: Frick Controls Quantum HD version 10.22 and prior.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Johnson Controls
Product Frick Controls Quantum HD
Versions Default: unaffected
  • Version Frick Controls Quantum HD version 10.22 and prior is affected

Solutions

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above. The update procedure can be found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories

Credits

  • Noam Moshe of Claroty Team 82 Research group finder

References

Problem Types

  • CWE-23: Relative Path Traversal CWE

Impacts

  • CAPEC-126 Path Traversal