PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-26381 Johnson Controls Inc. CVE debrief

Johnson Controls OpenBlue Mobile Web Application for OpenBlue Workplace versions 2025.1.2 and prior contain a Direct Request vulnerability that could allow an attacker to gain unauthorized access to sensitive information. The vulnerability was disclosed by CISA on December 4, 2025, with a CVSS 3.1 score of 9.3 (Critical). The attack vector is network-based, requires no privileges or user interaction, and can affect resources beyond the vulnerable component scope.

Vendor
Johnson Controls Inc.
Product
OpenBlue Mobile Web Application for OpenBlue Workplace
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-12-04
Original CVE updated
2025-12-04
Advisory published
2025-12-04
Advisory updated
2025-12-04

Who should care

Organizations using Johnson Controls OpenBlue Workplace with the Mobile Web Application enabled, particularly in building automation and smart building environments. Security teams responsible for ICS/OT infrastructure, facility managers, and system integrators deploying OpenBlue solutions should prioritize assessment and remediation.

Technical summary

The vulnerability exists in the OpenBlue Mobile Web Application for OpenBlue Workplace, where improper access controls allow direct requests to sensitive resources without proper authorization. The CVSS 3.1 score of 9.3 reflects network attackability, low attack complexity, no required privileges or user interaction, scope change to affected resources, high confidentiality impact, and low integrity impact. The CVSS 4.0 vector indicates attack complexity remains low with partial attack requirements, high confidentiality and scope confidentiality impacts, and low integrity and scope integrity impacts.

Defensive priority

critical

Recommended defensive actions

  • Upgrade to patch level 2025.1.3 or above when available. If patch is applied, no further mitigation steps are required.
  • If patch is unavailable, disable the Mobile Application in Microsoft Internet Information Services (IIS) at the application pool level.
  • As an alternative workflow, use the primary OpenBlue Workplace web interface at [base url]/FMInteract/Default.aspx?DashboardType=Homepage for functionality previously accessed via the Mobile interface.
  • For detailed mitigation instructions, consult Johnson Controls Product Security Advisory JCI-PSA-2025-05 v1.
  • Apply network segmentation to limit exposure of ICS/OT systems to untrusted networks.
  • Implement defense-in-depth strategies for industrial control systems environments.

Evidence notes

Source: CISA CSAF advisory ICSA-25-338-03. CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N. Affected versions: 2025.1.2 and prior.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-26381 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-26381

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-26381 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-26381

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-338-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-338-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.