Johnson Controls OpenBlue Employee (FMS Employee) Multiple Vulnerabilities
First seen Aug 2, 2026 · Updated Aug 2, 2026 · CVSS 2.4
CISA disclosed three low-to-medium severity vulnerabilities in Johnson Controls OpenBlue Employee (FMS Employee) versions <=V2025.3.1, including unrestricted file upload, stored XSS, and HTML injection flaws. Exploitation requires authenticated access and user interaction, limiting practical risk, though successful attacks could allow malicious file uploads, persistent script execution, or content manipulation within the application. No public exploitation has been reported.
Technical Analysis
CVE-2026-21662 (CWE-434) allows unrestricted upload of dangerous file types due to inadequate content-type validation, potentially placing malicious files in predictable storage locations. CVE-2026-34495 (CWE-79) enables stored XSS, where attacker-supplied JavaScript persists in the application database and executes against other users viewing affected pages. CVE-2026-34497 (CWE-80) permits HTML injection, allowing DOM manipulation and content spoofing without full script execution. All three vulnerabilities carry CVSSv3.1 scores of 2.4 (LOW) due to required privileges and user interaction, though CVSSv4.0 rates them slightly higher at 4.8 (MEDIUM). This is a facility/building management employee-portal application; it is not an AI agent or LLM tool-use component, and no plausible agent-system impact is indicated by the available data.
Affected Systems
Johnson Controls OpenBlue Employee (FMS Employee) versions <=V2025.3.1 [LV1.1]
Indicators of Compromise
- None reported - no known public exploitation observed
Remediation Steps
- 1
Apply vendor update
Update OpenBlue Employee (FMS Employee) beyond V2025.3.1 per Johnson Controls advisory JCI-PSA-2026-09.
- 2
Restrict access and enforce authentication
Limit application access to authorized users only and require strong authentication mechanisms.
- 3
Disable unused file features
Enable the 'Do Not Show Files' location setting if file-sharing functionality is not actively required.
- 4
Deploy a Web Application Firewall
Use a WAF to detect and block malicious upload attempts and script injection payloads.
- 5
Audit uploaded content
Periodically review and remove suspicious or unnecessary uploaded files from the application.
- 6
Limit network exposure
Restrict access to trusted networks or VPN connections; avoid direct internet exposure of the application and underlying control systems.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.