← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 13, 2026 · 12:00via CISA Alerts

Johnson Controls Metasys

Brief

View CSAF

Summary

Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access.

The following versions of Johnson Controls Metasys are affected:

  • Metasys 12 vers:all/* (CVE-2026-34491)
  • Metasys 13 vers:all/* (CVE-2026-34491)
  • Metasys 14
  • Metasys 15

CVSS

Vendor

Equipment

Read more on CISA Alerts