Junglewise Threat Intelligence

CVE-2026-21662: Johnson Controls FM Systems Employee unrestricted file upload

CVE-2026-21662 · Severity: info · CVSS 4.8 · Published 2026-07-31

Executive brief

Johnson Controls FM Systems Employee, a workplace management tool, is vulnerable to an unrestricted file upload flaw. An attacker with high-level administrative privileges could upload malicious files to the system, potentially compromising the integrity of the application. This could lead to unauthorized changes or the introduction of malicious content within the employee management environment.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in Johnson Controls FM Systems Employee versions prior to 2025.3.1. The flaw allows an authenticated attacker with high privileges (PR:H) to upload files of dangerous types to the server. Exploitation requires some level of user interaction (UI:P). Successful exploitation could allow the attacker to place malicious files on the system, potentially leading to code execution or data manipulation depending on the server configuration. The issue is addressed in version 2025.3.1.

Affected products

  • Johnson Controls FM Systems Employee before 2025.3.1

Timeline

  • 2026-07-31: advisory: Initial disclosure by Johnson Controls
  • 2025.3.1: patched: Vulnerability fixed in this version

References

Related threats