Johnson Controls recommends applying the latest available patches for affected Metasys versions. Metasys 15.0: patch released 2026-03-25. Metasys 14.1.5: forecast release 2026-07-15. Metasys 16.0: not impacted. Metasys 12 and 13: end of support, upgrade to later version. Additional measures: restrict network access to the Metasys UI to trusted networks, implement network segmentation, enforce least-privilege access controls, implement Content Security Policy headers, deploy a web application firewall, and monitor for suspicious URL patterns and script execution in access logs.
Quick answers
What is CVE-2026-34491?
Johnson Controls recommends applying the latest available patches for affected Metasys versions. Metasys 15.0: patch released 2026-03-25. Metasys 14.1.5: forecast release 2026-07-15. Metasys 16.0: not impacted. Metasys 12 and 13: end of support, upgrade to later version. Additional measures: restrict network access to the Metasys UI to trusted networks, implement network segmentation, enforce least-privilege access controls, implement Content Security Policy headers, deploy a web application firewall, and monitor for suspicious URL patterns and script execution in access logs.
How severe is CVE-2026-34491?
high, CVSS 8.6
Is CVE-2026-34491 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-34491 be mitigated?
Johnson Controls recommends applying the latest available patches for affected Metasys versions. Metasys 15.0: patch released 2026-03-25. Metasys 14.1.5: forecast release 2026-07-15. Metasys 16.0: not impacted. Metasys 12 and 13: end of support, upgrade to later version. Additional measures: restrict network access to the Metasys UI to trusted networks, implement network segmentation, enforce least-privilege access controls, implement Content Security Policy headers, deploy a web application firewall, and monitor for suspicious URL patterns and script execution in access logs.
CVSS
8.6
Vendor
Johnson Controls Inc
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Johnson Controls Metasys 12, Johnson Controls Metasys 13, Johnson Controls Metasys 14 (pre-14.1.5), Johnson Controls Metasys 15 (pre-15.0.1)
Mitigation
Johnson Controls recommends applying the latest available patches for affected Metasys versions. Metasys 15.0: patch released 2026-03-25. Metasys 14.1.5: forecast release 2026-07-15. Metasys 16.0: not impacted. Metasys 12 and 13: end of support, upgrade to later version. Additional measures: restrict network access to the Metasys UI to trusted networks, implement network segmentation, enforce least-privilege access controls, implement Content Security Policy headers, deploy a web application firewall, and monitor for suspicious URL patterns and script execution in access logs.
Johnson Controls Metasys versions 12 and 13 are affected by a persistent cross-site scripting vulnerability (CVE-2026-34491). A low-privilege user can inject a malicious payload via a crafted URL that executes in the browser context of other users, including administrators. The vulnerability has been assigned CVSS scores of 8.0 (v3.1) and 8.6 (v4.0), reflecting high severity. Patches have been released for Metasys 15.0, while Metasys 14.1.5 is forecast for release in July 2026. Metasys 16.0 is not impacted. Versions 12 and 13 are end-of-support and require upgrading to a later version.