Junglewise Threat Intelligence

CVE-2026-34491: Johnson Controls Metasys cross-site scripting vulnerability

CVE-2026-34491 · Severity: info · Published 2026-08-24

Vendors: Johnson Controls.

Executive brief

Johnson Controls Metasys is a building automation and facility management system used to control HVAC, security, and other building infrastructure. A cross-site scripting (XSS) vulnerability allows attackers to inject malicious code into web pages viewed by administrators or operators, potentially leading to session hijacking, credential theft, or unauthorized control of building systems.

Technical details

This is a reflected or stored cross-site scripting (XSS) vulnerability caused by improper neutralization of user-supplied input during web page generation in the Metasys web interface. The vulnerability affects Metasys versions 14 before 14.1.5 and version 15 before 15.0.1. An attacker can craft a malicious link or inject script content that executes in the context of an authenticated user's browser, allowing credential or session token theft. The attack requires either social engineering to trick a user into clicking a link or stored XSS if input validation is bypassed during data storage. Patches are available in Metasys 14.1.5 and 15.0.1.

Affected products

  • Johnson Controls Metasys 14 before 14.1.5, 15 before 15.0.1

Timeline

  • 2026-08-24: disclosed

References