← Incidents
INCIDENT 111PhishingLOW / UNDER REVIEWSourced
Johnson Controls Metasys
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-14.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access.</strong></p> <p>The following versions of Johnson Controls Metasys are affected:</p> <ul> <li>Metasys 12 vers:all/* (CVE-2026-34491…
Last evidence update
13 AUG 2026 · 12:00 UTC
Source count
1
Status
reported
ManufacturingEnergyGovernmentTransportationDefenseCVE-2026-34491
Observation history
How this record has evolved as evidence accumulated.
18 AUG · 18:23 UTC
Initial report
Evidence