CISA Details Credential Exposure Flaw in Johnson Controls Simplex Incident Manager

Cleartext Credentials Found in Memory

The Cybersecurity and Infrastructure Security Agency published ICS advisory ICSA-26-232-01 on August 20, 2026, disclosing a vulnerability in Johnson Controls Simplex Incident Manager, a fire and life-safety incident-management application used across critical manufacturing, commercial facilities, government facilities, transportation systems and energy sites worldwide. Tracked as CVE-2026-27875, the flaw stores user credentials, including passwords and authentication tokens, in an unencrypted form in system memory while the application is running.

CISA assigned the vulnerability a CVSS v3.1 base score of 5.8 (medium), rating it CWE-316, Cleartext Storage of Sensitive Information in Memory. A local attacker with low privileges, or an insider with memory-dumping tools, could extract the exposed credentials and use them for unauthorized access to the application and connected systems. Exploitation requires local access to the host, and CISA rates the attack complexity as high.

Patch Available

Johnson Controls has released version v2.01.01 to address the flaw and published Product Security Advisory JCI-PSA-2026-28 with mitigation guidance. CISA and the vendor recommend upgrading affected Simplex Incident Manager deployments (v2.01 and earlier), restricting local system access to authorized personnel, deploying endpoint monitoring to detect memory-dumping activity, enforcing least-privilege access controls, and using full-disk encryption and secure boot to reduce the risk of offline memory analysis.

Johnson Controls reported the vulnerability to CISA. No public evidence of active exploitation has been disclosed.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *