Cyber Resilience
← All news

Johnson Controls OpenBlue Employee

Our takeJohnson Controls fixed file upload, stored XSS, and HTML injection flaws in OpenBlue Employee <=2025.3.1. Update to a fixed version if you use it.
Sources (1)
What this means for you — Security leader:Update all OpenBlue Employee (FMS Employee) instances to a version newer than 2025.3.1 to address three vulnerabilities that allow arbitrary file upload, stored XSS, and HTML injection.
What this means for you — Lean IT orgs:If you use Johnson Controls OpenBlue Employee software, update it past version 2025.3.1 right away. These flaws let attackers upload bad files or run malicious scripts.
What this means for you — MSP:Audit client environments for any Johnson Controls OpenBlue Employee (FMS Employee) deployments running ≤2025.3.1 and schedule immediate updates to close file-upload and stored-XSS vectors.
What this means for you — Researcher:Review the three CVEs and associated CSAF for details on the file-upload and stored-XSS vectors in OpenBlue Employee ≤2025.3.1.