A vulnerability was found in JohnsonControls AC2000 on Windows. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Configuration File Handler. The manipulation leads to uncontrolled search path.

This vulnerability is documented as CVE-2026-21661. The attack needs to be performed locally. There is not any exploit available.

Upgrading the affected component is advised.