discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Johnson Controls Metasys Vulnerability Exposes Users to Persistent Malicious Payloads

A vulnerability in Johnson Controls Metasys allows a low-privilege user to inject a persistent malicious payload via a crafted URL, potentially leading to session hijacking and unauthorized access.

By CISA·Aug 13·cisa.gov·3 min read

Intelligence analysis by Llama

A vulnerability in Johnson Controls Metasys exposes users to persistent malicious payloads, allowing a low-privilege user to inject a malicious XSS payload into the Metasys UI via a crafted URL.

Why it matters

This vulnerability affects multiple versions of Johnson Controls Metasys, including Metasys 12, 13, 14, and 15, and could allow an attacker to inject a persistent malicious payload, potentially leading to session hijacking and unauthorized access.

Imagine you're using a computer to control a building's temperature. If someone finds a way to trick the computer into doing something bad, they could make the temperature go crazy or even let someone else control it. This is what's happening with the Johnson Controls Metasys vulnerability. It's like a backdoor that lets someone do bad things to the computer.

Analysis

Background

The Johnson Controls Metasys vulnerability affects multiple versions of the software, including Metasys 12, 13, 14, and 15. The vulnerability allows a low-privilege user to inject a persistent malicious payload via a crafted URL, potentially leading to session hijacking and unauthorized access.

Affected Products

The following products are affected by this vulnerability:

  • Johnson Controls Metasys 12: vers:all/* (CVE-2026-34491)
  • Johnson Controls Metasys 13: vers:all/* (CVE-2026-34491)
  • Johnson Controls Metasys 14: <v14.1.5
  • Johnson Controls Metasys 15: <v15.0.1

Remediations

Johnson Controls recommends the following actions to mitigate the vulnerability:

  • Apply the latest available patches for affected Metasys versions
  • Upgrade to Metasys version 16.0 or apply the latest available patch for your version (15.0.1 or 14.1.5 when available)
  • Restrict network access to the Metasys UI to trusted networks and users only; do not expose the interface directly to the internet
  • Implement network segmentation to isolate building automation systems from the corporate IT network
  • Enforce least-privilege access controls – limit user accounts to the minimum permissions necessary
  • Implement Content Security Policy (CSP) headers and other HTTP security headers where possible at the network/proxy level
  • Monitor for suspicious URL patterns and unexpected script execution in Metasys UI access logs
  • Use a web application firewall (WAF) in front of the Metasys UI to detect and block common XSS payloads
  • Educate users to avoid clicking on untrusted or unexpected links that target the Metasys UI

Metrics

The CVSS version base score for this vulnerability is 8, with a base severity vector string of 3.1. The vulnerability is rated as HIGH, with a base severity vector string of 4.0. The vulnerability is exploitable via a network attack, with a base severity vector string of AV:N. The vulnerability is exploitable via a user interface attack, with a base severity vector string of AC:L. The vulnerability is exploitable via a low-privilege user attack, with a base severity vector string of PR:L. The vulnerability is exploitable via a remote attack, with a base severity vector string of UI:R. The vulnerability is exploitable via a user attack, with a base severity vector string of S:U. The vulnerability is exploitable via a high-privilege user attack, with a base severity vector string of C:H. The vulnerability is exploitable via a high-privilege user attack, with a base severity vector string of I:H. The vulnerability is exploitable via a high-privilege user attack, with a base severity vector string of A:H.

Acknowledgments

An anonymous researcher reported this vulnerability to Johnson Controls.

Key points

  • A vulnerability in Johnson Controls Metasys allows a low-privilege user to inject a persistent malicious payload via a crafted URL.
  • The vulnerability affects multiple versions of Johnson Controls Metasys, including Metasys 12, 13, 14, and 15.
  • Johnson Controls recommends applying the latest available patches for affected Metasys versions and upgrading to Metasys version 16.0 or applying the latest available patch for your version (15.0.1 or 14.1.5 when available).
  • Implementing network segmentation, least-privilege access controls, and Content Security Policy (CSP) headers will help to mitigate the vulnerability.
  • Educating users to avoid clicking on untrusted or unexpected links that target the Metasys UI is also crucial in preventing exploitation.
The Upside

If the vulnerability is patched quickly, the risk of exploitation will decrease, and users will be safer. Additionally, the implementation of network segmentation and least-privilege access controls will help to mitigate the vulnerability.

The Downside

If the vulnerability is not patched quickly, it could lead to widespread exploitation, resulting in significant financial losses and reputational damage for Johnson Controls. Furthermore, the lack of proper security measures, such as network segmentation and least-privilege access controls, will make it easier for attackers to exploit the vulnerability.

Originally reported at

cisa.gov

Discernion covers the story. Read the full piece at the source.

Tagsics-advisoryindustrial-control-systemsvulnerabilitycross-site-scriptingpersistent-malicious-payloadsession-hijackingunauthorized-access

Author

CISA

Intelligence analysis by

Llama

Published

Aug 13, 2026

Source

cisa.gov

Share

Topics

ics-advisoryindustrial-control-systemsvulnerabilitycross-site-scriptingpersistent-malicious-payloadsession-hijackingunauthorized-access

Related

More from this desk

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·thehackernews.com

Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. agencies warn of AI-powered attacks on Siemens S7 Series PLCs as a GitLab code-injection flaw (CVE-2026-19478) faces active exploitation, alongside npm supply-chain attacks and suspected Russian espionage clusters.