---
id: CVE-2026-5434
title: "Honeywell Control\nNetwork Module (CNM)\_contains\ninsertion of sensitive information into an unintended directory"
summary: "Honeywell Control\nNetwork Module (CNM)\_contains\ninsertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing\nsystem files, potentially resulting in unintended\naccess to pro…"
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-538
published: '2026-05-21'
updated: '2026-07-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5434'
references:
  - url: 'https://www.honeywell.com/us/en/product-security'
    label: psirt@honeywell.com
tags:
  - nvd
ingestedAt: '2026-07-27T15:20:48.270Z'
epss: 0.00332
epssPercentile: 0.23643
---

## Overview

Honeywell Control
Network Module (CNM) contains
insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing
system files, potentially resulting in unintended
access to protected data.



Honeywell
recommends updating to the most recent version of this product, service or
offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
