CVE-2026-34491: Johnson Controls Metasys 14 vulnerability
Published Aug 24, 2026
·Updated
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting.
This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1.
Affected Software
2 affected components
Johnson Controls Metasys 14<14.1.5
Johnson Controls Metasys 15<15.0.1
Event History
Aug 24, 2026
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Metasys releases are affected?
Metasys 14 releases before 14.1.5 and Metasys 15 releases before 15.0.1 are affected.
2
What is the impact of this issue?
The vulnerability allows cross-site scripting during web page generation because input is not properly neutralized.