Executive brief
Johnson Controls FM:Systems Employee, a workplace management tool, is affected by a security vulnerability that could allow an attacker to inject malicious scripts into the application. If exploited, these scripts could execute in the browser of other users, potentially leading to unauthorized actions or data access within the platform. This issue is resolved in version 2025.3.1.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in Johnson Controls FM Systems Employee versions prior to 2025.3.1. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with high privileges can inject malicious scripts that are stored on the server and subsequently executed in the context of another user's browser session when they view the affected page. The attack requires network connectivity and some user interaction. The vulnerability is addressed in version 2025.3.1.
Affected products
- Johnson Controls FM Systems Employee before 2025.3.1
Timeline
- 2026-07-31: advisory: Initial publication of CVE-2026-34495 by Johnson Controls
- 2025.3.1: patched: Vulnerability fixed in this version