[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-johnson-controls-openblue-employee-app-has-file-upload-flaws":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},4857,"johnson-controls-openblue-employee-app-has-file-upload-flaws","Johnson Controls OpenBlue Employee App Has File Upload Flaws","Three low-to-medium severity bugs in the facilities-management app could let an attacker upload malicious files or inject scripts, CISA warns.","Johnson Controls' facilities-management web app has three bugs that let a logged-in user plant scripts or sneak files past the front door.\n\nCISA's advisory (ICSA-26-211-02) covers OpenBlue Employee, also called FMS Employee, in versions V2025.3.1 and earlier. Three separate flaws are involved: an unrestricted file upload bug (CVE-2026-21662), a stored cross-site scripting flaw (CVE-2026-34495), and an HTML injection issue (CVE-2026-34497). All three require an authenticated user with elevated privileges to trigger, and two also need someone to interact with the malicious content, which is why the CVSS scores land low on the 3.1 scale (2.4) and only medium on the newer 4.0 scale (4.8). Johnson Controls, the Ireland-headquartered building-systems company, reported the bugs itself and has published a patch along with a mitigation checklist under advisory JCI-PSA-2026-09.\n\nOpenBlue is JCI's smart-building platform, deployed across critical manufacturing, commercial facilities, transportation, energy, and government sites worldwide, so an attacker who compromises one authorized account gains a foothold in whatever dashboard actually manages a building's systems. The privilege and interaction requirements keep the CVSS numbers modest, but that access level is exactly what phished credentials or a disgruntled insider already have.\n\nA low CVSS score does not mean low stakes when the software in question sits between an attacker and the systems running a factory floor or an airport terminal.","[\"johnson-controls\",\"openblue\",\"ics-security\",\"vulnerability\"]","2026-07-30T12:00:00.000Z","2026-08-14T02:13:31.775Z","2026-08-14T02:13:43.553Z","published",null,[],"security",[26,27,28,29],"johnson-controls","openblue","ics-security","vulnerability",[31],{"name":32,"url":33},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-211-02",0,{"sections":36},[37,42,45,50,55,60,65,70,75,80,85,90,95,100],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",3293,"2026-08-20T04:00:00.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":41},"Security",435,{"name":46,"slug":47,"count":48,"latest_published_at":49},"Policy","policy",210,"2026-08-19T09:32:27.000Z",{"name":51,"slug":52,"count":53,"latest_published_at":54},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Hardware","hardware",140,"2026-08-19T18:25:42.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":69},"Science","science",90,"2026-08-19T18:41:02.000Z",{"name":71,"slug":72,"count":73,"latest_published_at":74},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":76,"slug":77,"count":78,"latest_published_at":79},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Startups","startups",47,"2026-08-19T19:13:46.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":91,"slug":92,"count":93,"latest_published_at":94},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]