# Persistent XSS Flaw Hits Johnson Controls Metasys

Published: 2026-08-13 · Severity: routine · Sectors: manufacturing, government-national, transportation, energy
Canonical: https://vorant.io/reports/44f406bf-1610-5e18-b741-8a212ece57b6/persistent-xss-flaw-hits-johnson-controls-metasys

> A stored XSS vulnerability in Johnson Controls Metasys building automation software could let low-privilege users hijack admin sessions via a crafted URL.

CISA published an ICS advisory for a persistent cross-site scripting vulnerability (CVE-2026-34491) affecting Johnson Controls Metasys building automation systems, versions 12 through 15 (pre-15.0.1/14.1.5). The flaw allows a low-privilege user to inject a malicious payload via a crafted URL that persists across logins and executes in the browser context of other users, including administrators, potentially enabling session hijacking and unauthorized access.

No public exploitation has been reported. Johnson Controls has released patches for Metasys 15.0 and plans a fix for 14.1.5, while versions 12 and 13 are end-of-support and should be upgraded. Version 16.0 is unaffected. Mitigations include restricting network access to the Metasys UI, network segmentation from corporate IT, least-privilege enforcement, CSP/HTTP security headers, WAF deployment, and monitoring for anomalous URL patterns. Given Metasys's deployment across critical manufacturing, commercial facilities, government, transportation, and energy sectors worldwide, unpatched instances present a meaningful risk if the UI is exposed or accessible to untrusted users.

## Mentioned in this report

- Vulnerabilities: CVE-2026-34491

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-14

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/44f406bf-1610-5e18-b741-8a212ece57b6/persistent-xss-flaw-hits-johnson-controls-metasys.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
