<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Metasys - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/metasys/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 13 Aug 2026 16:52:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/metasys/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS Vulnerability in Johnson Controls Metasys</title><link>https://feed.craftedsignal.io/briefs/2026-08-metasys-xss/</link><pubDate>Thu, 13 Aug 2026 16:52:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-metasys-xss/</guid><description>A stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-34491) in Johnson Controls Metasys allows low-privileged users to execute arbitrary scripts in the context of other users' sessions, potentially leading to session hijacking.</description><content:encoded><![CDATA[<p>Johnson Controls Metasys versions 12, 13, 14, and 15 contain a critical Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-34491. This vulnerability exists because the Metasys UI fails to properly neutralize input during web page generation. An attacker with low-level user privileges can inject a persistent malicious payload via a crafted URL. This payload is stored and subsequently executed within the browser context of any user who views the manipulated URL, including administrative accounts. Successful exploitation could allow an attacker to hijack user sessions, perform unauthorized actions within the building automation system, or gain administrative-level access to the management interface. This flaw poses a significant risk to critical infrastructure sectors, including energy, government services, and transportation, where Metasys is deployed worldwide.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability enables attackers to perform actions on behalf of authenticated administrators, leading to unauthorized control of facility management systems. Given the nature of these building automation systems, compromise could lead to operational disruption, loss of monitoring, or access to sensitive environmental controls. There are currently no reports of this vulnerability being exploited in the wild, but the high CVSS score (8.0/8.6) necessitates immediate attention for systems exposed to internal or external networks.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the latest available patches provided by Johnson Controls: Upgrade to Metasys 16.0, or patch to version 15.0.1 or 14.1.5 (when available).</li>
<li>Restrict access to the Metasys UI by enforcing network segmentation, ensuring the interface is not exposed to the internet, and limiting access to trusted networks and users.</li>
<li>Implement Content Security Policy (CSP) headers at the proxy or WAF level to mitigate the impact of injected scripts.</li>
<li>Monitor Metasys UI access logs for suspicious URL patterns or unexpected script-based payloads.</li>
<li>Enforce the principle of least privilege to minimize the potential impact if a standard user account is compromised.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>industrial-control-systems</category><category>xss</category><category>web-vulnerability</category></item></channel></rss>