Cross-Site Scripting Vulnerability in Johnson Controls FM Systems Employee Software
CVE-2026-34495

4.8MEDIUM

Key Information:

Vendor
CVE Published:
31 July 2026

What is CVE-2026-34495?

An input validation flaw in the Johnson Controls FM Systems Employee software allows attackers to exploit stored cross-site scripting (XSS). This vulnerability enables malicious script to be executed in the browser of unsuspecting users, potentially leading to unauthorized access and data manipulation. It is essential for users of FM Systems Employee prior to version 2025.3.1 to take proactive measures to mitigate this risk.

Affected Version(s)

FM Systems Employee 0 < 2025.3.1

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.