Johnson Controls Metasys
View CSAF Summary Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access. The following versions of Johnson Controls Metasys are affected: Metasys 12 vers:all/* (CVE-2026-34491) Metasys 13 vers:all/* (CVE-2026-34491) Metasys 14 Metasys 15 CVSS Vendor Equipment Vulnerabilities v3 8 Johnson Controls Inc Johnson Controls Metasys Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-34491 A low-privilege user can inject a malicious XSS payload into the Metasys UI via a crafted URL. The payload persists across logins and executes in the browser context of other users, including administrators. View CVE Details Affected Products Johnson Controls Metasys Vendor: Johnson Controls Inc Product Version: Johnson Controls Inc Metasys 12: vers:all/*, Johnson Controls Inc Metasys 13: vers:all/*, Johnson Controls Inc Metasys 14: <v14.1.5, Johnson Controls Inc Metasys 15: <v15.0.1 Product Status: known_affected Remediations Mitigation Johnson Controls recommends the following actions: Mitigation User are recommended to apply the latest available patches for affected Metasys versions Mitigation Metasys 16.0: Not impacted, fixed prior to release Vendor fix Metasys 15.0: Patch released 2026-03-25 Vendor fix Metasys 14.1.5: Forecast release 2026-07-15 Vendor fix Metasys 13: End of support, update to later version Vendor fix Metasys 12: End of support, update to later version Mitigation Metasys 11 & prior: Not affected (vulnerability introduced at version
CSIRTS triage
- What
- Persistent cross-site scripting vulnerability via crafted URL injection that executes in other users' sessions including administrators.
- Who is affected
- Metasys versions 12, 13, 14, and 15 deployments.
- Urgency
- Critical; stored XSS enabling session hijacking of administrative users.
- Action
- Apply vendor patch or upgrade to fixed Metasys version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Metasys
Get an email when a new Metasys advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-14
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-34491 | coverage & exploitation status | NVD · CVE.org |
More from CISA Cybersecurity Advisories
- criticalSiemens Siveillance Video2026-08-13
- criticalFlow Neuroscience FL-1002026-08-13
- criticalSiemens LOGO! Soft Comfort2026-08-13
- criticalANDRITZ HIPASE-250 and 250 SCALA2026-08-13
- criticalJohnson Controls Inc. Airwall2026-08-13