Johnson Controls Simplex Incident Manager Vulnerable to Credential Theft
A critical vulnerability in Johnson Controls Simplex Incident Manager allows local attackers to steal user credentials from system memory.

CISA has issued an advisory detailing a significant security flaw in Johnson Controls' Simplex Incident Manager software, specifically affecting versions up to and including V2.01. The vulnerability, identified as CVE-2026-27875, permits local attackers with minimal privileges to extract sensitive user credentials, such as passwords and authentication tokens, directly from the system's memory.
The core of the issue lies in the application's method of handling sensitive information. While running, Simplex Incident Manager stores user credentials in an unencrypted format within system memory. This cleartext storage makes the credentials vulnerable to extraction by any entity with local access to the affected system. Attackers could leverage memory-dumping tools or exploit insider privileges to gain access to this sensitive data, potentially leading to unauthorized access to the application itself and any connected systems.
The potential impact of this vulnerability is considerable, especially given the deployment of Simplex Incident Manager across critical infrastructure sectors worldwide. These sectors include Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, and Energy. The ability for a low-privilege local attacker to escalate their access by stealing credentials could compromise the operational integrity and security of these vital systems.
Johnson Controls has acknowledged the vulnerability and has released a patched version, v2.01.01, to address the issue. The company strongly recommends upgrading Simplex Incident Manager to version v1.01.05 or later to remediate the vulnerability. In addition to the patch, Johnson Controls advises implementing several defensive measures to further reduce the risk of exploitation.
These recommended mitigations include restricting local access to systems running Simplex Incident Manager to authorized personnel only, implementing robust endpoint protection and monitoring to detect suspicious processes or memory-dumping tools, and enforcing strong access control policies and the principle of least privilege on host systems. Furthermore, utilizing full-disk encryption and secure boot can help mitigate the risks associated with offline memory analysis, while continuous monitoring for unauthorized local access attempts and comprehensive audit logging are crucial for detecting and responding to potential breaches.
While no known public exploitation targeting this specific vulnerability has been reported to CISA at this time, its nature as a local privilege escalation flaw warrants prompt attention. The vulnerability is not remotely exploitable, and it carries a high attack complexity, suggesting that successful exploitation requires a degree of technical skill and local access. However, the cleartext storage of credentials remains a critical security weakness that could be exploited by malicious actors or insiders.
CISA emphasizes that organizations should conduct proper impact analysis and risk assessment before deploying any defensive measures. The agency also points to its extensive resources on control systems security, including best practices for Industrial Control Systems (ICS) cybersecurity and targeted cyber intrusion detection and mitigation strategies, to help organizations bolster their overall security posture.
This incident underscores the ongoing importance of secure coding practices and diligent vulnerability management, particularly for software deployed in critical infrastructure environments. The cleartext storage of sensitive information is a well-known vulnerability class, and its presence in a system like Simplex Incident Manager highlights the persistent challenges in securing operational technology (OT) environments.