Johnson Controls Metasys Vulnerability Exposes Users to Persistent Malicious Payloads
A vulnerability in Johnson Controls Metasys allows a low-privilege user to inject a persistent malicious payload via a crafted URL, potentially leading to session hijacking and unauthorized access.
Intelligence analysis by Llama
A vulnerability in Johnson Controls Metasys exposes users to persistent malicious payloads, allowing a low-privilege user to inject a malicious XSS payload into the Metasys UI via a crafted URL.
Imagine you're using a computer to control a building's temperature. If someone finds a way to trick the computer into doing something bad, they could make the temperature go crazy or even let someone else control it. This is what's happening with the Johnson Controls Metasys vulnerability. It's like a backdoor that lets someone do bad things to the computer.
Analysis
Background
The Johnson Controls Metasys vulnerability affects multiple versions of the software, including Metasys 12, 13, 14, and 15. The vulnerability allows a low-privilege user to inject a persistent malicious payload via a crafted URL, potentially leading to session hijacking and unauthorized access.
Affected Products
The following products are affected by this vulnerability:
- Johnson Controls Metasys 12: vers:all/* (CVE-2026-34491)
- Johnson Controls Metasys 13: vers:all/* (CVE-2026-34491)
- Johnson Controls Metasys 14: <v14.1.5
- Johnson Controls Metasys 15: <v15.0.1
Remediations
Johnson Controls recommends the following actions to mitigate the vulnerability:
- Apply the latest available patches for affected Metasys versions
- Upgrade to Metasys version 16.0 or apply the latest available patch for your version (15.0.1 or 14.1.5 when available)
- Restrict network access to the Metasys UI to trusted networks and users only; do not expose the interface directly to the internet
- Implement network segmentation to isolate building automation systems from the corporate IT network
- Enforce least-privilege access controls – limit user accounts to the minimum permissions necessary
- Implement Content Security Policy (CSP) headers and other HTTP security headers where possible at the network/proxy level
- Monitor for suspicious URL patterns and unexpected script execution in Metasys UI access logs
- Use a web application firewall (WAF) in front of the Metasys UI to detect and block common XSS payloads
- Educate users to avoid clicking on untrusted or unexpected links that target the Metasys UI
Metrics
The CVSS version base score for this vulnerability is 8, with a base severity vector string of 3.1. The vulnerability is rated as HIGH, with a base severity vector string of 4.0. The vulnerability is exploitable via a network attack, with a base severity vector string of AV:N. The vulnerability is exploitable via a user interface attack, with a base severity vector string of AC:L. The vulnerability is exploitable via a low-privilege user attack, with a base severity vector string of PR:L. The vulnerability is exploitable via a remote attack, with a base severity vector string of UI:R. The vulnerability is exploitable via a user attack, with a base severity vector string of S:U. The vulnerability is exploitable via a high-privilege user attack, with a base severity vector string of C:H. The vulnerability is exploitable via a high-privilege user attack, with a base severity vector string of I:H. The vulnerability is exploitable via a high-privilege user attack, with a base severity vector string of A:H.
Acknowledgments
An anonymous researcher reported this vulnerability to Johnson Controls.
Key points
- A vulnerability in Johnson Controls Metasys allows a low-privilege user to inject a persistent malicious payload via a crafted URL.
- The vulnerability affects multiple versions of Johnson Controls Metasys, including Metasys 12, 13, 14, and 15.
- Johnson Controls recommends applying the latest available patches for affected Metasys versions and upgrading to Metasys version 16.0 or applying the latest available patch for your version (15.0.1 or 14.1.5 when available).
- Implementing network segmentation, least-privilege access controls, and Content Security Policy (CSP) headers will help to mitigate the vulnerability.
- Educating users to avoid clicking on untrusted or unexpected links that target the Metasys UI is also crucial in preventing exploitation.
If the vulnerability is patched quickly, the risk of exploitation will decrease, and users will be safer. Additionally, the implementation of network segmentation and least-privilege access controls will help to mitigate the vulnerability.
If the vulnerability is not patched quickly, it could lead to widespread exploitation, resulting in significant financial losses and reputational damage for Johnson Controls. Furthermore, the lack of proper security measures, such as network segmentation and least-privilege access controls, will make it easier for attackers to exploit the vulnerability.



