SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-34497

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

A Cross-Site Scripting (XSS) vulnerability exists in the FM Systems Employee application from Johnson Controls, allowing attackers to inject malicious scripts into web pages. This flaw can lead to unauthorized access to user data and session hijacking, posing a significant risk to users of the affected application. Organizations using versions prior to 2025.3.1 should prioritize remediation to protect against potential exploitation.

CVE
CVE-2026-34497
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%

Original NVD Description

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)