CVE-2026-21662 in FM Systems Employee is an unrestricted file upload vulnerability with a CVSS 9.8 — and the score is warranted. The flaw is network-accessible, requires no authentication, and allows dangerous type files to reach the server. That combination alone makes it critical. But the risk profile extends far beyond the web server.
Facilities management software like this sits at a boundary that most organizations don't adequately model: it bridges enterprise IT and the operational technology that runs buildings. FM Systems Employee frequently integrates with HVAC controls, access badge systems, energy management platforms, and IP-addressable building devices. Compromising the FM application doesn't just give you a web shell — it puts you inside the system that holds the asset inventory, network addresses, physical locations, and operational dependencies of every connected building system.
That's the real exposure. The vulnerability is the entry point; the asset database is the prize. An attacker with a foothold can map every IP-addressable device on the building network, identify legacy protocols with weak or absent authentication, and compile a target list for physical infrastructure compromise. The CVSS metric measures exploitability, not informational payload. This vulnerability exposes the blueprint of your physical security architecture.
Patch version 2025.3.1 addresses the file upload validation. What is not publicly clear is whether the fix implements content-based validation (magic byte verification, sandboxed parsing) or merely extension deny-listing — the latter is trivially bypassed. If you cannot immediately apply the patch, assume the vulnerability is exploitable and treat the FM system as already compromised: isolate it network-wise from OT systems, review access logs for anomalous file uploads, and audit the asset inventory database for unauthorized access or exfiltration.
The disclosure timeline is worth noting. The patch shipped in version 2025.3.1 but the CVE was published in 2026, creating a window where anyone monitoring vendor release notes could correlate the version jump with a security fix and identify vulnerable targets. Assume adversaries are aware.
Prioritize patching this. The operational risk is not a compromised document repository — it's a compromised map of your building's physical security infrastructure.