vulnerability
Johnson Controls OpenBlue Employee
High
Summary
Johnson Controls has released a security advisory (JCI-PSA-2026-09) addressing critical vulnerabilities in its OpenBlue Employee system. These vulnerabilities – including stored XSS, HTML injection, and file upload flaws – could allow attackers to execute malicious code, inject arbitrary HTML content, and potentially compromise the system. The advisory recommends applying the latest product update (<=V2025.3.1) and implementing additional mitigations such as limiting application access, enabling the "Do Not Show Files" setting, and employing a Web Application Firewall.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data