lowOther

Johnson Controls OpenBlue Employee (FMS Employee) Multiple Vulnerabilities

First seen Aug 2, 2026 · Updated Aug 2, 2026 · CVSS 2.4

ICSCISA-advisoryfile-uploadXSSHTML-injectionbuilding-management-systemJohnson-Controls

CISA disclosed three low-to-medium severity vulnerabilities in Johnson Controls OpenBlue Employee (FMS Employee) versions <=V2025.3.1, including unrestricted file upload, stored XSS, and HTML injection flaws. Exploitation requires authenticated access and user interaction, limiting practical risk, though successful attacks could allow malicious file uploads, persistent script execution, or content manipulation within the application. No public exploitation has been reported.

Technical Analysis

CVE-2026-21662 (CWE-434) allows unrestricted upload of dangerous file types due to inadequate content-type validation, potentially placing malicious files in predictable storage locations. CVE-2026-34495 (CWE-79) enables stored XSS, where attacker-supplied JavaScript persists in the application database and executes against other users viewing affected pages. CVE-2026-34497 (CWE-80) permits HTML injection, allowing DOM manipulation and content spoofing without full script execution. All three vulnerabilities carry CVSSv3.1 scores of 2.4 (LOW) due to required privileges and user interaction, though CVSSv4.0 rates them slightly higher at 4.8 (MEDIUM). This is a facility/building management employee-portal application; it is not an AI agent or LLM tool-use component, and no plausible agent-system impact is indicated by the available data.

Affected Systems

Johnson Controls OpenBlue Employee (FMS Employee) versions <=V2025.3.1 [LV1.1]

Indicators of Compromise

  • None reported - no known public exploitation observed

Remediation Steps

  1. 1

    Apply vendor update

    Update OpenBlue Employee (FMS Employee) beyond V2025.3.1 per Johnson Controls advisory JCI-PSA-2026-09.

  2. 2

    Restrict access and enforce authentication

    Limit application access to authorized users only and require strong authentication mechanisms.

  3. 3

    Disable unused file features

    Enable the 'Do Not Show Files' location setting if file-sharing functionality is not actively required.

  4. 4

    Deploy a Web Application Firewall

    Use a WAF to detect and block malicious upload attempts and script injection payloads.

  5. 5

    Audit uploaded content

    Periodically review and remove suspicious or unnecessary uploaded files from the application.

  6. 6

    Limit network exposure

    Restrict access to trusted networks or VPN connections; avoid direct internet exposure of the application and underlying control systems.

CVE / Advisory IDs

CVE-2026-21662CVE-2026-34495CVE-2026-34497

Industries Most Exposed

Critical ManufacturingCommercial FacilitiesGovernment Services and FacilitiesTransportation SystemsEnergy

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.