Medium severity5.4NVD Advisory· Published Jul 31, 2026· Updated Aug 10, 2026
CVE-2026-34495
CVE-2026-34495
Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS.
This issue affects FM Systems Employee: before 2025.3.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:johnsoncontrols:fms_employee:*:*:*:*:*:*:*:*Range: <=2025.3.1
- Range: <2025.3.1
Patches
Vulnerability mechanics
References
1- www.johnsoncontrols.com/trust-center/cybersecurity/security-advisoriesnvdVendor Advisory
News mentions
2- Johnson Controls OpenBlue Employee: Three Low-Severity Flaws Disclosed TogetherVypr Intelligence · Jul 30, 2026
- Johnson Controls OpenBlue EmployeeCISA ICS Advisories