Johnson Controls Metasys
A vulnerability in Johnson Controls Metasys allows a low-privilege user to inject malicious code via a crafted URL, potentially leading to session hijacking and unauthorized access across multiple versions. The vulnerability is critical and has been addressed with patches, but organizations should implement additional mitigations to reduce risk.
Johnson Controls Metasys has a critical vulnerability (CVE-2026-34491) that could allow a low-privilege user to inject a malicious Cross-Site Scripting (XSS) payload into the Metasys UI through a crafted URL. This payload persists across logins and executes in the browser context of other users, including administrators, potentially leading to unauthorized access. The vulnerability affects Metasys versions 12, 13, 14, and 15. Johnson Controls recommends applying the latest available patches, including Metasys 15.0 (released 2026-03-25) and Metasys 14.1.5 (forecast release 2026-07-15). Versions 12 and 13 are end-of-support and should be upgraded. To minimize risk, organizations are advised to restrict network access to the Metasys UI, implement network segmentation, enforce least-privilege access controls, and consider using a Web Application Firewall (WAF). An anonymous researcher reported this vulnerability to Johnson Controls. CISA recommends minimizing network exposure for control system devices and using secure remote access methods like VPNs, recognizing that VPNs themselves can have vulnerabilities. Organizations should perform impact analysis and risk assessments and report any suspected malicious activity to CISA.