CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-34497

criticalcovered by 2 sourcesfirst seen 2026-07-30
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions of Johnson Controls OpenBlue Employee are affected: OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497) CVSS Vendor Equipment Vulnerabilities v3 2.4 Johnson Controls Inc. Johnson Controls OpenBlue Employee Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-21662 The application does not adequately restrict the types of files that can be uploaded, allowing an attacker to submit files with dangerous content types. Uploaded files may be stored in predictable locations and could be leveraged for further exploitation against the application or its users. View CVE Details Affected Products Johnson Controls OpenBlue Employee Vendor: Johnson Controls Inc. Product Version: Johnson Controls Inc. OpenBlue Employee (FMS Employee): <=V2025.3.1 Product Status: known_affected Remediations Mitigation Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: Apply the latest product update for OpenBlue Employee (FMS Employee). Customers running V2025.3.1 [LV1.1] or earlier should apply the latest available update. Mitigation Limit application access to authorized users and enforce strong authentication. Mitigation Enable the "Do Not Show Files" location setting if the feature is not being actively used. Mitigation Employ a Web Application Firewall (WAF) to h

CSIRTS triage

vendor: Johnson Controls Inc.product: OpenBlue EmployeeCross-site request forgeryCross-site scriptingaffected: OpenBlue Employee (FMS Employee) <=V2025.3.1
What
Vulnerabilities allow file uploads, stored XSS attacks, and HTML content injection.
Who is affected
Users of Johnson Controls OpenBlue Employee versions up to and including V2025.3.1.
Urgency
Remediation is critical due to the potential for exploitation through file uploads and XSS.
Action
Update OpenBlue Employee to a version later than V2025.3.1.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-34497

Get an email if CVE-2026-34497 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-34497

CVE.org record

Embed the live status

CVE-2026-34497 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-34497 status](https://www.csirts.com/badge/CVE-2026-34497)](https://www.csirts.com/cve/CVE-2026-34497)