Johnson Controls Metasys
Brief
View CSAF
Summary
Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access.
The following versions of Johnson Controls Metasys are affected:
- Metasys 12 vers:all/* (CVE-2026-34491)
- Metasys 13 vers:all/* (CVE-2026-34491)
- Metasys 14
- Metasys 15
