← Back to Feed

Johnson Controls Metasys

CVE-2026-34491

August 13, 2026 · CISA (US-CERT) · Severity: CRITICAL

A stored cross-site scripting vulnerability (CVE-2026-34491) in Johnson Controls Metasys versions 12 through 15 allows low-privilege users to inject persistent payloads via crafted URLs. These payloads execute in the context of other users, including administrators, enabling session hijacking and unauthorized access. Patches are available for Metasys 15.0 and 14.1.5, while older versions are end-of-life and require upgrading.

Key Takeaways

  • CVE-2026-34491 is a stored XSS vulnerability in Johnson Controls Metasys UI affecting versions 12 through 15. Low-privilege users can inject persistent malicious payloads via crafted URLs that execute in admin sessions. Patches are available for Metasys 14.1.5 and 15.0; older versions require upgrades.
☕ Buy a Coffee