What is CVE-2026-34497?
This XSS vulnerability in Johnson Controls FM Systems Employee allows attackers to inject malicious scripts into web pages. Systems running versions prior to 2025.3.1 are affected, and immediate update to the latest version is recommended.
Azərbaycanca: Bu XSS zəifliyi Johnson Controls FM Systems Employee məhsulunda aşkarlanıb və təcavüzkara veb səhifəyə zərərli skriptlər yerləşdirməyə imkan verir. 2025.3.1 versiyasından əvvəlki sistemlər təsirə məruz qalır, dərhal proqram təminatını son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Johnson Controls
FAQ2
Which product is affected by CVE-2026-34497?
This XSS vulnerability was discovered in Johnson Controls FM Systems Employee.
What should be done to protect against this vulnerability?
Systems running versions prior to 2025.3.1 are affected, so immediate update to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.