Johnson Controls Metasys 12.x / 13.x / 14.x < 14.1.5 / 15.x < 15.0.1 Cross-Site Scripting (CVE-2026-34491)

high Tenable OT Security Plugin ID 505941

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A low-privilege user can inject a malicious XSS payload into the Johnson Controls Metasys UI via a crafted URL. The payload persists across logins and executes in the browser context of other users, including administrators.
Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access.

The vulnerability was introduced at Metasys version 12; Metasys 11 and prior are not affected, and Metasys 16.0 was fixed prior to release.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

The following text was originally created by the Cybersecurity and Infrastructure Security Agency (CISA). The original can be found at CISA.gov.

Upgrade to Metasys version 16.0 or apply the latest available patch for your version (15.0.1 or 14.1.5 when available). Metasys 12 and Metasys 13 are end of support; update to a later version.

For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-11.

See Also

https://tyco.widen.net/s/fq5rrvnwx2/jci-psa-2026-11

https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-14

https://www.johnsoncontrols.com/cyber-solutions/security-advisories

Plugin Details

Severity: High

ID: 505941

File Name: tenable_ot_johnsoncontrols_CVE-2026-34491.nasl

Version: 1.2

Type: Remote

Family: Tenable.ot

Published: 8/24/2026

Updated: 8/26/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.76

CVSS v3

Risk Factor: High

Base Score: 8.7

Temporal Score: 7.6

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.6

Threat Score: 6.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:johnsoncontrols:nae55_firmware, cpe:/o:johnsoncontrols:nae85_firmware, cpe:/o:johnsoncontrols:nie55_firmware, cpe:/o:johnsoncontrols:nie59_firmware, cpe:/o:johnsoncontrols:nie85_firmware

Required KB Items: Tenable.ot/JohnsonControls

Exploit Ease: No known exploits are available

Patch Publication Date: 3/25/2026

Vulnerability Publication Date: 8/13/2026

Reference Information

CVE: CVE-2026-34491

CWE: 79

IAVB: 2026-B-0236

ICSA: 26-225-14