Johnson Controls OpenBlue Employee
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions of Johnson Controls OpenBlue Employee are affected: OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497) CVSS Vendor Equipment Vulnerabilities v3 2.4 Johnson Controls Inc. Johnson Controls OpenBlue Employee Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-21662 The application does not adequately restrict the types of files that can be uploaded, allowing an attacker to submit files with dangerous content types. Uploaded files may be stored in predictable locations and could be leveraged for further exploitation against the application or its users. View CVE Details Affected Products Johnson Controls OpenBlue Employee Vendor: Johnson Controls Inc. Product Version: Johnson Controls Inc. OpenBlue Employee (FMS Employee): <=V2025.3.1 Product Status: known_affected Remediations Mitigation Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: Apply the latest product update for OpenBlue Employee (FMS Employee). Customers running V2025.3.1 [LV1.1] or earlier should apply the latest available update. Mitigation Limit application access to authorized users and enforce strong authentication. Mitigation Enable the "Do Not Show Files" location setting if the feature is not being actively used. Mitigation Employ a Web Application Firewall (WAF) to h
CSIRTS triage
- What
- Vulnerabilities allow file uploads, stored XSS attacks, and HTML content injection.
- Who is affected
- Users of Johnson Controls OpenBlue Employee versions up to and including V2025.3.1.
- Urgency
- Remediation is critical due to the potential for exploitation through file uploads and XSS.
- Action
- Update OpenBlue Employee to a version later than V2025.3.1.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch OpenBlue Employee
Get an email when a new OpenBlue Employee advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-21662 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34495 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34497 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownCVE-2026-34497: Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in…nvd
- unknownCVE-2026-34495: Improper neutralization of input during web page generation ('cross-site scripting') vulnerabi…nvd
- unknownCVE-2026-21662: Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems E…nvd
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalMZ Automation GmbH libiec618502026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30