Johnson Controls Metasys Cross-Site Scripting Vulnerability (CVE-2026-34491)
Persistent XSS in Metasys UI allows low-privilege users to execute payloads in administrator sessions
Key Takeaways
- Persistent XSS vulnerability (CVE-2026-34491) affects Johnson Controls Metasys versions 12, 13, 14 (pre-14.1.5), and 15 (pre-15.0.1).
- Exploitation allows a low-privilege user to inject a payload that executes in the browser context of other users, including administrators.
- CVSS scores of 8.0 (v3.1) and 8.6 (v4.0) reflect high severity.
- Patches released for Metasys 15.0; Metasys 14.1.5 forecast for July 2026; Metasys 16.0 not impacted.
- Metasys 12 and 13 are end-of-support; upgrading is recommended.
Quick answers
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


