CVE-2026-34495: FMS Employee vulnerable to XSS
Published Jul 31, 2026
·Updated
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS.
This issue affects FM Systems Employee: before 2025.3.1.
Affected Software
2 affected components
Johnson Controls FM Systems Employee<2025.3.1
Johnsoncontrols Fms Employee<=2025.3.1
Event History
Jul 31, 2026
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-34495?
The severity of CVE-2026-34495 is medium with a CVSS score of 4.8.
2
What software is affected by CVE-2026-34495?
The vulnerability CVE-2026-34495 affects Johnson Controls FM Systems Employee versions before 2025.3.1.
3
How do I fix CVE-2026-34495?
To fix CVE-2026-34495, upgrade to Johnson Controls FM Systems Employee version 2025.3.1 or later.
4
What type of vulnerability is CVE-2026-34495?
CVE-2026-34495 is a cross-site scripting (XSS) vulnerability.
5
What can be exploited in CVE-2026-34495?
CVE-2026-34495 allows attackers to store malicious scripts in FM Systems Employee, leading to potential data theft or session hijacking.