Security & Threat Intelligence · 30.07.2026, 17:34 UTC
Johnson Controls OpenBlue Employee
| Schweregrad | info |
|---|---|
| CVE | ↗ ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 30.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-21662, CVE-2026-34495, CVE-2026-34497. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions of Johnson Controls OpenBlue Employee are affected:
OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497)
CVSS Vendor Equipment Vulnerabilities
v3 2.4 Johnson Controls Inc. Johnson Controls OpenBlue Employee Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Background
Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-21662
The application does not adequately restrict the types of files that can be uploaded, allowing an attacker to submit files with dangerous content types. Uploaded files may be stored in predictable locations and could be leveraged for further exploitation against the application or its users. View CVE Details
Affected Products Johnson Controls OpenBlue Employee
Vendor:Johnson Controls Inc. Product Version:Johnson Controls Inc. OpenBlue Employee (FMS Employee): <=V2025.3.1 Product Status:known_affected
Remediations MitigationJohnson Controls recommends the following defensive measures to help reduce the risk of …