Johnson Controls Metasys

View CSAF
Summary
Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users’ sessions, including administrators, potentially leading to session hijacking and unauthorized access.
The following versions of Johnson Controls Metasys are affected:

Metasys 12 vers:all/* (CVE-2026-34491)
Metasys 13 vers:all/* (CVE-2026-34491)
Metasys 14
Metasys 15

CVSS
Vendor
Eq…

📰 来源: CISA 安全公告

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部