CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Johnson Controls OpenBlue Employee

criticalCVE-2026-21662CVE-2026-34495CVE-2026-34497
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions of Johnson Controls OpenBlue Employee are affected: OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497) CVSS Vendor Equipment Vulnerabilities v3 2.4 Johnson Controls Inc. Johnson Controls OpenBlue Employee Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-21662 The application does not adequately restrict the types of files that can be uploaded, allowing an attacker to submit files with dangerous content types. Uploaded files may be stored in predictable locations and could be leveraged for further exploitation against the application or its users. View CVE Details Affected Products Johnson Controls OpenBlue Employee Vendor: Johnson Controls Inc. Product Version: Johnson Controls Inc. OpenBlue Employee (FMS Employee): <=V2025.3.1 Product Status: known_affected Remediations Mitigation Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: Apply the latest product update for OpenBlue Employee (FMS Employee). Customers running V2025.3.1 [LV1.1] or earlier should apply the latest available update. Mitigation Limit application access to authorized users and enforce strong authentication. Mitigation Enable the "Do Not Show Files" location setting if the feature is not being actively used. Mitigation Employ a Web Application Firewall (WAF) to h

CSIRTS triage

vendor: Johnson Controls Inc.product: OpenBlue EmployeeCross-site request forgeryCross-site scriptingaffected: OpenBlue Employee (FMS Employee) <=V2025.3.1
What
Vulnerabilities allow file uploads, stored XSS attacks, and HTML content injection.
Who is affected
Users of Johnson Controls OpenBlue Employee versions up to and including V2025.3.1.
Urgency
Remediation is critical due to the potential for exploitation through file uploads and XSS.
Action
Update OpenBlue Employee to a version later than V2025.3.1.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch OpenBlue Employee

Get an email when a new OpenBlue Employee advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-07-30
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-21662coverage & exploitation statusNVD · CVE.org
CVE-2026-34495coverage & exploitation statusNVD · CVE.org
CVE-2026-34497coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories