Johnson Controls OpenBlue Employee
Low RiskCVSS 2.4ICS-CERT ICSA-26-211-02Jul 30, 2026
Johnson Controls
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityLow
User InteractionRequired
Summary
OpenBlue Employee (FMS Employee) versions V2025.3.1 and earlier contain vulnerabilities allowing file upload, stored cross-site scripting (XSS), and HTML injection attacks. An attacker with administrative credentials could upload malicious files or inject code that executes when other users access the application, potentially compromising their systems or stealing facility management data.
What this means
What could happen
An attacker with administrative credentials could upload malicious files or inject malicious code into the OpenBlue Employee web application, potentially compromising workstations that access it or the data it stores.
Who's at risk
Facility managers and operations staff who use Johnson Controls OpenBlue Employee (FMS Employee) for building and facility management are affected. This includes municipal facility operations teams and any organization relying on this web application for facility scheduling, asset management, or employee services.
How it could be exploited
An attacker with administrative access to OpenBlue Employee could exploit file upload or cross-site scripting vulnerabilities to upload a malicious file or inject JavaScript code. When authorized users access the application through a web browser, they would unknowingly execute the attacker's code, potentially leading to credential theft or lateral movement within your facility network.
Prerequisites
- Administrative credentials for OpenBlue Employee
- Network access to the OpenBlue Employee web interface
- User interaction required (a legitimate user must visit the compromised page)
Requires administrative credentials to exploitRequires user interactionLow severity (CVSS 2.4)Remotely exploitable via web interface
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
OpenBlue Employee (FMS Employee)≤ V2025.3.1No fix yet
Remediation & Mitigation
0/6
Do now
0/4HARDENINGRestrict OpenBlue Employee web access to authorized personnel only using network segmentation, IP whitelisting, or authentication proxy
HARDENINGEnforce multi-factor authentication (MFA) for all OpenBlue Employee administrative accounts
WORKAROUNDDisable the 'Show Files' location setting in OpenBlue Employee if not actively used
HARDENINGAudit OpenBlue Employee for suspicious uploaded files or modified content and remove any found
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXUpdate OpenBlue Employee (FMS Employee) to the latest available version beyond V2025.3.1
WORKAROUNDDeploy a Web Application Firewall (WAF) in front of OpenBlue Employee to detect and block file upload attacks and script injection attempts
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/b3459f40-086a-4ba9-b03f-35153ce12f61Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.