VYPR
advisoryPublished Aug 13, 2026· 1 source

Critical XSS Vulnerability Discovered in Johnson Controls Metasys

CISA alerts users to a critical cross-site scripting vulnerability in Johnson Controls Metasys, potentially enabling session hijacking and unauthorized access.

CISA has issued a critical alert regarding CVE-2026-34491, a cross-site scripting (XSS) vulnerability affecting multiple versions of Johnson Controls' Metasys building automation system. The vulnerability, rated as HIGH severity with a CVSS v3.1 base score of 8.0, allows a low-privilege user to inject a persistent malicious payload via a crafted URL. This payload can then execute within the context of other users' sessions, including those of administrators, posing a significant risk of session hijacking and unauthorized system access.

The vulnerability specifically impacts Johnson Controls Metasys versions 12, 13, 14, and 15. While Metasys 12 and 13 are noted as end-of-support, versions 14 and 15 have specific patch levels that address the issue. Metasys 14 is fixed in versions 14.1.5 and later, while Metasys 15 is addressed in versions 15.0.1 and later. Metasys version 16.0 is not impacted, as the vulnerability was fixed prior to its release.

Successful exploitation could lead to severe consequences, including unauthorized access to sensitive building management data, manipulation of environmental controls, and potential disruption of critical infrastructure operations. The persistence of the payload means that even after a user logs out and back in, the malicious script can continue to execute, making it a potent threat for persistent compromise.

Johnson Controls has provided specific vendor fixes and recommended users apply the latest available patches. For older, end-of-support versions like Metasys 12 and 13, the company strongly advises updating to a later, supported version. The advisory also details a comprehensive list of mitigation strategies for organizations to implement, aiming to reduce the attack surface and prevent exploitation.

These mitigation measures include restricting network access to the Metasys UI, implementing network segmentation to isolate building automation systems from corporate networks, enforcing least-privilege access controls, and deploying security headers like Content Security Policy (CSP). Additionally, organizations are advised to monitor Metasys UI access logs for suspicious activity, utilize web application firewalls (WAFs), and educate users about the risks of clicking untrusted links.

CISA emphasizes the importance of minimizing network exposure for all control system devices, ensuring they are not directly accessible from the internet. They recommend locating control system networks behind firewalls and isolating them from business networks, using secure methods like VPNs for remote access, and keeping all systems updated. Organizations are encouraged to perform thorough impact analyses and risk assessments before deploying any defensive measures.

While no known public exploitation specifically targeting this vulnerability has been reported to CISA at this time, the critical nature of the flaw and its potential impact on critical infrastructure sectors like Critical Manufacturing, Commercial Facilities, and Energy, necessitate prompt attention from affected organizations. The vulnerability was reported by an anonymous researcher to Johnson Controls, highlighting the ongoing efforts of the security community in identifying and reporting such flaws.

Synthesized by Vypr AI