๐Ÿ” CVE Alert

CVE-2026-34491

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1.

Vendor johnson controls
Product metasys 14
Published Aug 24, 2026
Stay Ahead of the Next One

Get instant alerts for johnson controls metasys 14

Be the first to know when new unknown vulnerabilities affecting johnson controls metasys 14 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Johnson Controls / Metasys 14
0 < 14.1.5
Johnson Controls / Metasys 15
0 < 15.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
johnsoncontrols.com: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories