HomeIntelligenceBrief
VULNERABILITY BRIEF🟢 Low Vulnerability

Multiple Web Vulnerabilities (CVE‑2026‑21662, CVE‑2026‑34495, CVE‑2026‑34497) in Johnson Controls OpenBlue Employee Enable Malicious File Upload & XSS

Johnson Controls’ OpenBlue Employee platform (≤ V2025.3.1) contains three CVEs that permit unrestricted file uploads and cross‑site scripting. The flaws map to SOC 2 CC6 controls, making timely patching essential for audit readiness.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 cisa.gov
🟢
Severity
Low
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
5 recommended
📰
Source
cisa.gov

Multiple Web Vulnerabilities (CVE‑2026‑21662, CVE‑2026‑34495, CVE‑2026‑34497) in Johnson Controls OpenBlue Employee Enable Malicious File Upload & XSS

What It Is – The OpenBlue Employee (formerly FMS Employee) building‑management application contains three linked flaws: an unrestricted file‑upload (CVE‑2026‑21662) and two cross‑site scripting issues (CVE‑2026‑34495, CVE‑2026‑34497). An attacker could store malicious files in predictable locations, execute stored XSS payloads, or inject arbitrary HTML into user‑facing pages.

Exploitability – No public exploit code has been released, but the CVSS v3 base score is 2.4 (Low). The advisory notes that successful exploitation is possible if the vulnerable version (≤ V2025.3.1) remains unpatched.

Affected Products – Johnson Controls OpenBlue Employee (all releases up to and including version 2025.3.1).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping – The flaws map directly to SOC 2 CC6.1 (Logical Access) and CC6.2 (System Operations) requirements for input validation and secure file handling. Demonstrating remediation shows you’re meeting those criteria.
  • Continuous Evidence – Patching, configuration hardening, and automated scanning generate audit‑ready logs that can be fed into a Trust Center for real‑time compliance proof.
  • Enterprise Buyer Expectations – Critical‑infrastructure customers now request documented remediation of web‑app vulnerabilities as part of their SOC 2 vendor‑assessment checklists.

Recommended Actions

  • Inventory all OpenBlue Employee instances and verify version numbers.
  • Apply Johnson Controls’ security patch (or upgrade to > V2025.3.1) immediately.
  • Enforce strict file‑type whitelisting and store uploads outside the web root.
  • Conduct a code‑review or automated SAST scan to confirm XSS mitigations.
  • Map the remediation steps to SOC 2 CC6.1/CC6.2 controls and capture the change‑management tickets as audit evidence.

Source: CISA Advisory – ICSA‑26‑211‑02

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →