Johnson Controls Metasys

Summary

Johnson Controls Metasys versions 12, 13, 14, and 15 are affected by CVE-2026-34491, a cross-site scripting vulnerability. Successful exploitation allows a low-privilege user to inject a persistent malicious payload via a crafted URL, potentially leading to session hijacking and unauthorized access.

IFF Assessment

FOE

The article details a cross-site scripting vulnerability that can be exploited to hijack administrator sessions, posing a significant risk to defenders.

Severity

8.0 High

The CVSS score of 8.0 reflects the severity of the vulnerability, which allows for a low-privilege user to inject a persistent malicious payload that executes in the context of other users' sessions, including administrators, leading to potential unauthorized access and session hijacking.

Defender Context

Defenders should be aware of this cross-site scripting vulnerability in Johnson Controls Metasys systems, which are deployed in critical infrastructure sectors. Prompt patching and monitoring for suspicious URL patterns or session hijacking attempts are crucial to mitigate the risk of unauthorized access and data compromise.

Read Full Story →