logo

Johnson Controls OpenBlue Mobile Web Application for OpenBlue Workplace

ID: 8db25c3c-b8c8-54fd-be54-4e5dbae3fda0

STIX ID: report--8db25c3c-b8c8-54fd-be54-4e5dbae3fda0

Feed Name: All CISA Advisories

Threat Score
75/100

Date Published: 2025-12-04

Date Updated: 2026-07-30

Author: CISA

...
...

Johnson Controls and CISA published an advisory for CVE-2025-26381, a Direct Request ('Forced Browsing') vulnerability in OpenBlue Mobile Web Application (<= 2025.1.2) that may allow remote, low-complexity access to sensitive information; CVSS v3.1 is 9.3 (critical) and CVSS v4 is 6.5 (base), mitigations include upgrading to 2025.1.3 or disabling the mobile application in IIS and following CISA/Johnson Controls guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.