CVE-2026-34491
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1.
| Vendor | johnson controls |
| Product | metasys 14 |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for johnson controls metasys 14
Be the first to know when new unknown vulnerabilities affecting johnson controls metasys 14 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Johnson Controls / Metasys 14
0 < 14.1.5
Johnson Controls / Metasys 15
0 < 15.0.1