Johnson Controls Metasys Persistent Cross-Site Scripting Vulnerability (CVE-2026-34491)
First seen Aug 15, 2026 · Updated Aug 15, 2026 · CVSS 8
A high-severity persistent cross-site scripting vulnerability affects Johnson Controls Metasys building automation systems (versions 12–15), allowing a low-privilege user to inject a malicious payload via a crafted URL that executes in other users' sessions, including administrators. This could lead to session hijacking and unauthorized access within critical infrastructure environments such as commercial facilities, manufacturing, energy, and government sites. No public exploitation has been reported to CISA at this time, but patches or vendor guidance are available for supported versions.
Technical Analysis
CVE-2026-34491 is a CWE-79 (Improper Neutralization of Input During Web Page Generation) vulnerability in the Metasys UI that enables persistent XSS: a low-privilege authenticated user crafts a malicious URL whose payload persists across logins and executes in the browser context of other users, including administrators, enabling session hijacking, privilege escalation, and unauthorized system access. The flaw scores 8.0 (CVSS v3.1, AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) and 8.6 (CVSS v4.0), reflecting network-exploitable, low-complexity attack requiring low privileges and user interaction. Affected versions include Metasys 12 and 13 (both end-of-support, no patch planned), Metasys 14 (fix forecast 2026-07-15), and Metasys 15 (patched 2026-03-25); Metasys 16 and 11-and-earlier are unaffected. This is a traditional ICS/OT web-interface vulnerability with no direct AI agent or LLM tooling exposure, though organizations running AI-driven building management copilots or agentic automation tied to Metasys dashboards should ensure any credentials or API tokens used by such integrations are not exposed via hijacked administrator sessions.
Affected Systems
Johnson Controls Metasys 12 (all versions, end of support), Metasys 13 (all versions, end of support), Metasys 14 (<v14.1.5, patch forecast 2026-07-15), Metasys 15 (<v15.0.1, patched 2026-03-25). Metasys 16.0 and Metasys 11 and earlier are not affected.
Indicators of Compromise
- No known IOCs published; no public exploitation reported to CISA at this time.
Remediation Steps
- 1
Upgrade or patch affected versions
Upgrade to Metasys 16.0 or apply the latest patch for your version (15.0.1 or 14.1.5 when released). Metasys 12 and 13 are end-of-support and should be upgraded to a supported version.
- 2
Restrict network exposure
Do not expose the Metasys UI directly to the internet; restrict access to trusted internal networks and authorized users only.
- 3
Network segmentation
Isolate building automation systems from corporate IT networks using firewalls and segmentation.
- 4
Enforce least privilege
Limit user accounts on Metasys to the minimum permissions necessary to reduce impact of compromised low-privilege accounts.
- 5
Deploy web security controls
Implement Content Security Policy (CSP) headers, other HTTP security headers, and a WAF in front of the Metasys UI to detect and block XSS payloads.
- 6
Monitor and detect
Monitor Metasys UI access logs for suspicious URL patterns and unexpected script execution.
- 7
User awareness
Educate users to avoid clicking untrusted or unexpected links targeting the Metasys UI.
- 8
Review vendor advisory
Consult Johnson Controls Product Security Advisory JCI-PSA-2026-11 for detailed mitigation instructions.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.