CVE-2026-21662: FMS Employee Allows Upload of Unrestricted Files
Published Jul 31, 2026
·Updated
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.
This issue affects FM Systems Employee: before 2025.3.1.
Affected Software
2 affected components
FM Systems Employee<2025.3.1
Johnsoncontrols Fms Employee<=2025.3.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FM Systems Employeeto a version that resolves this vulnerability.Fixed in 2025.3.1
Event History
Jul 31, 2026
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21662?
CVE-2026-21662 has a medium severity rating of 4.8 based on CVSS.
2
How do I fix CVE-2026-21662?
To mitigate CVE-2026-21662, ensure you update to FM Systems Employee version 2025.3.1 or later.
3
What does CVE-2026-21662 involve?
CVE-2026-21662 involves an unrestricted file upload vulnerability that could allow malicious files to be uploaded in FM Systems Employee.
4
Which software is affected by CVE-2026-21662?
CVE-2026-21662 affects FM Systems Employee versions prior to 2025.3.1.
5
When was CVE-2026-21662 published?
CVE-2026-21662 was published on July 31, 2026.