Cross-Site Scripting Vulnerability in Johnson Controls Metasys Products
CVE-2026-34491
6.1MEDIUM
What is CVE-2026-34491?
A vulnerability in Johnson Controls Metasys Products allows for improper neutralization of input during web page generation, leading to cross-site scripting. Affected versions include Metasys 14 prior to 14.1.5 and Metasys 15 prior to 15.0.1. This flaw could enable attackers to inject malicious scripts, potentially compromising the integrity of user interactions with the affected systems.
Affected Version(s)
Metasys 14 0 < 14.1.5
Metasys 15 0 < 15.0.1
