VYPR
Medium severityNVD Advisory· Published Aug 24, 2026· Updated Sep 3, 2026

CVE-2026-34491

CVE-2026-34491

Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting.

This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

1