What is CVE-2026-34495?
CVE-2026-34495 is a Stored XSS vulnerability in Johnson Controls FM Systems Employee due to improper neutralization of input during web page generation. This affects versions before 2025.3.1. Immediate update to version 2025.3.1 is recommended.
Azərbaycanca: CVE-2026-34495, Johnson Controls FM Systems Employee proqramında aşkarlanmış saxlanılan XSS zəifliyidir. Bu, veb səhifənin yaradılması zamanı daxiletmələrin düzgün zərərsizləşdirilməməsi səbəbindən baş verir. Proqramın 2025.3.1 versiyasından əvvəlki versiyaları təsirlənir. Təcili olaraq 2025.3.1 versiyasına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Johnson Controls
FAQ2
In which software was CVE-2026-34495 discovered?
In Johnson Controls FM Systems Employee software.
Which version is recommended to remediate this XSS vulnerability?
Update to version 2025.3.1 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.