Johnson Controls Metasys Building Automation Platform Patches Persistent XSS Vulnerability

Crafted URL Can Hijack Administrator Sessions

CISA published ICS advisory ICSA-26-225-14 on August 13, 2026, disclosing a cross-site scripting vulnerability in Johnson Controls Metasys, a building automation and management platform used across critical manufacturing, commercial facilities, government facilities, transportation systems and energy sites worldwide. Tracked as CVE-2026-34491 and rated CWE-79, the flaw carries a CVSS v3 base score of 8.0.

According to CISA, a low-privilege user can inject a malicious payload into the Metasys web interface through a crafted URL. The payload persists across logins and executes in the browser context of other users who view the affected page, including administrators, which could lead to session hijacking and unauthorized access to building systems. The advisory lists Metasys 12 and 13 as affected in all versions, and Metasys 14 before v14.1.5 and Metasys 15 before v15.0.1.

Mitigation

Johnson Controls has released patched versions for the affected Metasys 14 and 15 branches and published mitigation guidance for the platform. CISA recommends operators apply the available updates, restrict Metasys web interface access to trusted networks, and follow standard input-validation and session-management hardening for building management system deployments.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *