CVE-2026-34497: FMS Employee Vulnerable to HTML Injection
Published Jul 31, 2026
·Updated
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS).
This issue affects FM Systems Employee: before 2025.3.1.
Affected Software
2 affected components
FM Systems Employee<2025.3.1
Johnsoncontrols Fms Employee<=2025.3.1
Event History
Jul 31, 2026
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-34497?
CVE-2026-34497 has a risk score of 35, indicating it is a low to moderate severity vulnerability.
2
How do I fix CVE-2026-34497?
To mitigate the effects of CVE-2026-34497, upgrade FM Systems Employee to version 2025.3.1 or later.
3
What kind of vulnerability is CVE-2026-34497?
CVE-2026-34497 is classified as an HTML injection vulnerability, specifically a Cross-Site Scripting (XSS) issue.
4
Which systems are affected by CVE-2026-34497?
CVE-2026-34497 affects FM Systems Employee versions prior to 2025.3.1.
5
When was CVE-2026-34497 published?
CVE-2026-34497 was published on July 31, 2026.