Johnson Controls Metasys
Plan PatchCVSS 8ICS-CERT ICSA-26-225-14Aug 13, 2026
Johnson Controls
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary
Persistent cross-site scripting (XSS) vulnerability in Johnson Controls Metasys allows a low-privilege user to inject malicious code via crafted URL that executes in other users' browser sessions. Successful exploitation could lead to session hijacking, unauthorized access, and unauthorized control of building automation systems. Affects Metasys 12, 13, 14 (prior to v14.1.5), and 15 (prior to v15.0.1).
What this means
What could happen
An attacker with low-privilege access could inject malicious code into Metasys that runs in other users' sessions, including administrators, potentially allowing them to hijack accounts and gain unauthorized control of building automation systems.
Who's at risk
Building automation operators and facility managers using Johnson Controls Metasys to manage HVAC, lighting, and other building systems. This affects Metasys versions 12, 13, 14, and 15 deployed in commercial buildings, hospitals, data centers, and other facilities.
How it could be exploited
An attacker with low-privilege Metasys credentials crafts a malicious URL containing JavaScript code and tricks an administrator or other user into clicking it. When the user opens the link, the injected code runs in their browser session with their privileges, allowing the attacker to steal session tokens, modify system settings, or perform actions as that user.
Prerequisites
- Low-privilege Metasys user account
- Ability to trick a higher-privileged user into clicking a malicious link
- Network access to Metasys web interface
remotely exploitablelow complexitylow-privilege attacker sufficientsocial engineering required
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (4)
4 with fix
ProductAffected VersionsFix Status
Metasys 12All versionsFix available
Metasys 13All versionsFix available
Metasys 14<v14.1.5Fix available
Metasys 15<v15.0.1Fix available
Remediation & Mitigation
0/6
Do now
0/2HARDENINGRestrict Metasys web interface access to trusted networks using firewall rules
HARDENINGTrain users to avoid clicking links from untrusted sources that direct to Metasys
Schedule — requires maintenance window
0/4Patching may require device reboot — plan for process interruption
Metasys 15
HOTFIXUpdate Metasys 15 to version 15.0.1 or later (patch available 2026-03-25)
Metasys 14
HOTFIXUpdate Metasys 14 to version 14.1.5 or later (patch forecast for 2026-07-15)
Metasys 13
HOTFIXUpdate Metasys 13 to the latest available patch from Johnson Controls
Metasys 12
HOTFIXUpdate Metasys 12 to the latest available patch from Johnson Controls
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/332c5b17-a845-4a08-99c9-a26ea327477dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.