highOther

Johnson Controls Metasys Persistent Cross-Site Scripting Vulnerability (CVE-2026-34491)

First seen Aug 15, 2026 · Updated Aug 15, 2026 · CVSS 8

icsotbuilding-automationxsscwe-79johnson-controlsmetasyscisa-advisory

A high-severity persistent cross-site scripting vulnerability affects Johnson Controls Metasys building automation systems (versions 12–15), allowing a low-privilege user to inject a malicious payload via a crafted URL that executes in other users' sessions, including administrators. This could lead to session hijacking and unauthorized access within critical infrastructure environments such as commercial facilities, manufacturing, energy, and government sites. No public exploitation has been reported to CISA at this time, but patches or vendor guidance are available for supported versions.

Technical Analysis

CVE-2026-34491 is a CWE-79 (Improper Neutralization of Input During Web Page Generation) vulnerability in the Metasys UI that enables persistent XSS: a low-privilege authenticated user crafts a malicious URL whose payload persists across logins and executes in the browser context of other users, including administrators, enabling session hijacking, privilege escalation, and unauthorized system access. The flaw scores 8.0 (CVSS v3.1, AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) and 8.6 (CVSS v4.0), reflecting network-exploitable, low-complexity attack requiring low privileges and user interaction. Affected versions include Metasys 12 and 13 (both end-of-support, no patch planned), Metasys 14 (fix forecast 2026-07-15), and Metasys 15 (patched 2026-03-25); Metasys 16 and 11-and-earlier are unaffected. This is a traditional ICS/OT web-interface vulnerability with no direct AI agent or LLM tooling exposure, though organizations running AI-driven building management copilots or agentic automation tied to Metasys dashboards should ensure any credentials or API tokens used by such integrations are not exposed via hijacked administrator sessions.

Affected Systems

Johnson Controls Metasys 12 (all versions, end of support), Metasys 13 (all versions, end of support), Metasys 14 (<v14.1.5, patch forecast 2026-07-15), Metasys 15 (<v15.0.1, patched 2026-03-25). Metasys 16.0 and Metasys 11 and earlier are not affected.

Indicators of Compromise

  • No known IOCs published; no public exploitation reported to CISA at this time.

Remediation Steps

  1. 1

    Upgrade or patch affected versions

    Upgrade to Metasys 16.0 or apply the latest patch for your version (15.0.1 or 14.1.5 when released). Metasys 12 and 13 are end-of-support and should be upgraded to a supported version.

  2. 2

    Restrict network exposure

    Do not expose the Metasys UI directly to the internet; restrict access to trusted internal networks and authorized users only.

  3. 3

    Network segmentation

    Isolate building automation systems from corporate IT networks using firewalls and segmentation.

  4. 4

    Enforce least privilege

    Limit user accounts on Metasys to the minimum permissions necessary to reduce impact of compromised low-privilege accounts.

  5. 5

    Deploy web security controls

    Implement Content Security Policy (CSP) headers, other HTTP security headers, and a WAF in front of the Metasys UI to detect and block XSS payloads.

  6. 6

    Monitor and detect

    Monitor Metasys UI access logs for suspicious URL patterns and unexpected script execution.

  7. 7

    User awareness

    Educate users to avoid clicking untrusted or unexpected links targeting the Metasys UI.

  8. 8

    Review vendor advisory

    Consult Johnson Controls Product Security Advisory JCI-PSA-2026-11 for detailed mitigation instructions.

CVE / Advisory IDs

CVE-2026-34491

Industries Most Exposed

Critical ManufacturingCommercial FacilitiesGovernment Services and FacilitiesTransportation SystemsEnergy

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.