Johnson Controls OpenBlue Employee: Three Low-Severity Flaws Disclosed Together
Key findings • Three low-severity vulnerabilities disclosed in Johnson Controls OpenBlue Employee on July 30, 2026. • Vulnerabilities include HTML injection, unrestricted file upload, and sto…
Key findings
- Three low-severity vulnerabilities disclosed in Johnson Controls OpenBlue Employee on July 30, 2026.
- Vulnerabilities include HTML injection, unrestricted file upload, and stored XSS.
- Exploitation could lead to web content manipulation and further system compromise.
- Affected versions are OpenBlue Employee (FMS Employee) <=V2025.3.1.
On July 30, 2026, three low-severity vulnerabilities were disclosed in Johnson Controls' OpenBlue Employee software. These vulnerabilities, all disclosed simultaneously, include HTML injection, unrestricted file upload, and stored cross-site scripting (XSS). Successful exploitation could allow an attacker to inject arbitrary HTML, upload malicious files, or execute stored XSS attacks, potentially manipulating web content or leading to further exploitation.
The HTML injection vulnerability (CVE-2026-34497) occurs when user-controlled input is embedded into web pages without proper sanitization, enabling attackers to alter the Document Object Model (DOM) and change the visual presentation of web content.
The unrestricted file upload vulnerability (CVE-2026-21662) arises from inadequate restrictions on file types that can be uploaded. Attackers can submit files with dangerous content types, which may be stored in predictable locations and used for further attacks.
The stored XSS vulnerability (CVE-2026-34495) happens when the application stores malicious JavaScript code, which is then executed when other users access the affected pages. This persistent threat is particularly dangerous as the payload remains active.
According to CISA, all three vulnerabilities affect OpenBlue Employee (FMS Employee) versions V2025.3.1 and earlier. Johnson Controls has addressed these issues, and users are advised to update to patched versions to mitigate the risks.
These vulnerabilities, while low in severity, highlight the importance of secure coding practices in web applications. Users of Johnson Controls OpenBlue Employee should ensure their systems are updated to the latest versions to protect against potential manipulation of web content and further exploitation.