Description
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.

This issue affects FM Systems Employee: before 2025.3.1.
Published: 2026-07-31
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to upload arbitrary files of dangerous type through the FM Systems Employee interface. This unrestricted file upload can be exploited to place malicious content on the server, potentially leading to further compromise or denial of service if the uploaded files are executed or processed by the application.

Affected Systems

Johnson Controls FM Systems Employee before version 2025.3.1. The affected product is the FM Systems Employee application from Johnson Controls.

Risk and Exploitability

The CVSS score is 4.8, indicating moderate severity. The EPSS score is less than 1%, suggesting low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is via the application’s file upload functionality accessible to authenticated users; exploitation would require an attacker to submit a malicious file to the upload endpoint, but no evidence of code execution or privilege escalation is documented.

Generated by OpenCVE AI on August 2, 2026 at 04:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FM Systems Employee to version 2025.3.1 or later, which contains the fix for unrestricted upload.
  • Restrict file upload by configuring the application to allow only safe file types and enforce size limits, reducing the attack surface.
  • Deploy a Web Application Firewall or file integrity monitoring to detect and block the submission of suspicious files and to alert administrators of potential uploads.

Generated by OpenCVE AI on August 2, 2026 at 04:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Johnsoncontrols
Johnsoncontrols fm Systems Employee
Vendors & Products Johnsoncontrols
Johnsoncontrols fm Systems Employee

Fri, 31 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.
Title FMS Employee Allows Upload of Unrestricted Files
First Time appeared Johnson Controls
Johnson Controls fm Systems Employee
Weaknesses CWE-434
CPEs cpe:2.3:a:johnson_controls:fm_systems_employee:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls fm Systems Employee
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Johnson Controls Fm Systems Employee
Johnsoncontrols Fm Systems Employee Fms Employee
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-07-31T18:24:41.723Z

Reserved: 2026-01-02T13:23:28.170Z

Link: CVE-2026-21662

cve-icon Vulnrichment

Updated: 2026-07-31T18:24:38.220Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-31T18:17:13.650

Modified: 2026-08-10T19:55:41.870

Link: CVE-2026-21662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:32:30Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type