CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-34491

criticalcovered by 1 sourcefirst seen 2026-08-13
View CSAF Summary Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access. The following versions of Johnson Controls Metasys are affected: Metasys 12 vers:all/* (CVE-2026-34491) Metasys 13 vers:all/* (CVE-2026-34491) Metasys 14 Metasys 15 CVSS Vendor Equipment Vulnerabilities v3 8 Johnson Controls Inc Johnson Controls Metasys Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-34491 A low-privilege user can inject a malicious XSS payload into the Metasys UI via a crafted URL. The payload persists across logins and executes in the browser context of other users, including administrators. View CVE Details Affected Products Johnson Controls Metasys Vendor: Johnson Controls Inc Product Version: Johnson Controls Inc Metasys 12: vers:all/*, Johnson Controls Inc Metasys 13: vers:all/*, Johnson Controls Inc Metasys 14: <v14.1.5, Johnson Controls Inc Metasys 15: <v15.0.1 Product Status: known_affected Remediations Mitigation Johnson Controls recommends the following actions: Mitigation User are recommended to apply the latest available patches for affected Metasys versions Mitigation Metasys 16.0: Not impacted, fixed prior to release Vendor fix Metasys 15.0: Patch released 2026-03-25 Vendor fix Metasys 14.1.5: Forecast release 2026-07-15 Vendor fix Metasys 13: End of support, update to later version Vendor fix Metasys 12: End of support, update to later version Mitigation Metasys 11 & prior: Not affected (vulnerability introduced at version

CSIRTS triage

vendor: Johnson Controls Inc.product: MetasysCross-site scriptingaffected: Metasys 12 all versions, Metasys 13 all versions, Metasys 14, Metasys 15
What
Persistent cross-site scripting vulnerability via crafted URL injection that executes in other users' sessions including administrators.
Who is affected
Metasys versions 12, 13, 14, and 15 deployments.
Urgency
Critical; stored XSS enabling session hijacking of administrative users.
Action
Apply vendor patch or upgrade to fixed Metasys version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-34491

Get an email if CVE-2026-34491 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-34491

CVE.org record

Embed the live status

CVE-2026-34491 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-34491 status](https://www.csirts.com/badge/CVE-2026-34491)](https://www.csirts.com/cve/CVE-2026-34491)