Executive summary

CISA published on August 13, 2026 advisory ICSA-26-225-14 warning of a stored cross-site scripting (XSS) vulnerability in the web UI of Johnson Controls Metasys, the Building Management System (BMS) platform that controls HVAC, differential pressure of clean rooms, air quality, boilers, lighting and physical security systems in a large share of modern hospitals. An authenticated low-privilege user can inject a malicious payload via a crafted URL; when an administrator visits that URL, the script executes in their browser with their privileges, enabling session hijacking, persistence and escalation to full BMS control. The vulnerability is tracked as CVE-2026-34491, CVSS v4.0 8.6 (HIGH) with vector AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Affected versions are Metasys 12 and 13 (no patch — end-of-support) and Metasys 14 and 15 (patches available). Although CISA does not list Healthcare among the affected sectors, Metasys is deployed at scale in hospitals for temperature, humidity and pressure control in critical areas (operating rooms, ICU, hospital pharmacy, laboratories).

Key points

  • Affected product: Johnson Controls Metasys — BMS platform with web-accessible UI from the corporate network.
  • Affected versions: Metasys 12 and 13 (vers:all/*), Metasys 14 < v14.1.5, Metasys 15 < v15.0.1. Metasys 11 and earlier NOT affected (vulnerability introduced in v12).
  • CVE and vector: CVE-2026-34491 — persistent/stored XSS. CVSS v4.0 8.6 (HIGH), vector AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H.
  • Attack vector: a low-privilege user (maintenance technician, third-party vendor with support account) injects a malicious URL; when a BMS administrator opens it, the payload executes in their session context, enabling session hijacking, cookie theft and administrative actions.
  • Potential clinical impact: an attacker controlling the BMS can manipulate temperature, humidity and differential pressure of operating rooms, ICUs, isolation rooms, hospital pharmacies and laboratories, compromising patient safety, stability of thermolabile drugs and sterility of surgical areas. They can also disable fire detection or tamper with integrated CCTV.
  • Patches: Metasys 15.0 → patch released 2026-03-25; Metasys 14.1.5 → release planned 2026-07-15; Metasys 13 and 12 → end-of-support, no patch (mandatory migration).
  • Immediate mitigations: network segmentation (isolate BMS from IT network), WAF in front of Metasys UI, CSP headers, IP-based access restriction, MFA for administrative accounts, monitoring of UI access logs.
  • CISA sectors: Critical Manufacturing, Commercial Facilities, Government Services, Transportation, Energy. Healthcare not listed but Metasys is widely deployed in hospitals as critical BMS.

Regulatory implications

FDA (US)

Although Metasys is not an FDA-regulated medical device, its manipulation can affect the safe operation of environments where thermolabile drugs are stored, surgical procedures are conducted or biological samples are processed. Under 21 CFR 820 (Quality System Regulation) and section 524B of the FD&C Act (postmarket cybersecurity), an incident that causes patient harm via BMS failure may be reportable as an adverse event.

MDR (EU)

If the BMS controls environmental conditions of a medical device or of a pharmaceutical manufacturing zone, its failure may constitute a serious MDR incident under Art. 87 (≤15 days) and MDCG 2019-16 rev 1.

GDPR

The Metasys UI contains credentials and personal data of users (operators, technicians). A session hijacking exposes personal data — Art. 33 (≤72h) if confidentiality compromise is confirmed. Art. 9 if health data of personnel is involved.

NIS2 / ENS

Hospitals are essential entities under NIS2 (Annex I, health sector) and essential service operators under Spanish ENS (HIGH category, op.cont.4). The BMS is a critical support system and its compromise triggers obligations under Art. 21 NIS2 (risk management measures) and RD 311/2024 (ENS, op.cont.4).

HIPAA

Although Metasys does not store PHI, if the hospital shares the same Active Directory or SSO infrastructure between BMS and HIS/EHR, a compromised BMS session can facilitate lateral movement toward PHI systems. Indirect risk under §164.308 (administrative safeguards).

Recommendation

Immediate actions within the next 72 hours: (1) inventory all Metasys 12 and 13 instances in the hospital and plan migration to Metasys 16.0 (unaffected) before Q4 2026; (2) apply Metasys 15.0.1 and Metasys 14.1.5 patches as soon as they are available; (3) segment the BMS network into a dedicated VLAN with no routes to Internet or to the clinical/EHR network; (4) deploy a WAF with anti-XSS rules in front of the Metasys UI; (5) enforce MFA on all administrative BMS accounts and audit technician/third-party accounts; (6) review BMS access logs from the last 90 days looking for anomalous patterns (suspicious URLs, injected scripts, external IP access); (7) disable inactive accounts with BMS privileges; (8) verify physical security controls because the BMS also manages CCTV, access control and smoke detection.

30-day actions: migrate any Metasys 12/13 instance to Metasys 16.0, integrate the BMS into the central SOC with UI anomaly detection (CISA recommends monitoring suspicious URL patterns), and document the BMS in the hospital’s OT incident response plan.


Source: CISA ICSA-26-225-14 — Johnson Controls Metasys

This analysis is part of HealthSec, the weekly newsletter on healthcare cybersecurity.