Medium severity5.4NVD Advisory· Published Jul 31, 2026· Updated Aug 10, 2026
CVE-2026-34497
CVE-2026-34497
Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS).
This issue affects FM Systems Employee: before 2025.3.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:johnsoncontrols:fms_employee:*:*:*:*:*:*:*:*Range: <=2025.3.1
- Range: <2025.3.1
Patches
Vulnerability mechanics
References
1- www.johnsoncontrols.com/trust-center/cybersecurity/security-advisoriesnvdVendor Advisory
News mentions
2- Johnson Controls OpenBlue Employee: Three Low-Severity Flaws Disclosed TogetherVypr Intelligence · Jul 30, 2026
- Johnson Controls OpenBlue EmployeeCISA ICS Advisories