Johnson Controls Metasys
Summary
Johnson Controls Metasys versions 12, 13, 14, and 15 are affected by CVE-2026-34491, a cross-site scripting vulnerability. Successful exploitation allows a low-privilege user to inject a persistent malicious payload via a crafted URL, potentially leading to session hijacking and unauthorized access.
IFF Assessment
The article details a cross-site scripting vulnerability that can be exploited to hijack administrator sessions, posing a significant risk to defenders.
Severity
The CVSS score of 8.0 reflects the severity of the vulnerability, which allows for a low-privilege user to inject a persistent malicious payload that executes in the context of other users' sessions, including administrators, leading to potential unauthorized access and session hijacking.
Defender Context
Defenders should be aware of this cross-site scripting vulnerability in Johnson Controls Metasys systems, which are deployed in critical infrastructure sectors. Prompt patching and monitoring for suspicious URL patterns or session hijacking attempts are crucial to mitigate the risk of unauthorized access and data compromise.