VYPR
Low severity2.4NVD Advisory· Published Jul 30, 2026

Johnson Controls OpenBlue Employee

CVE-2026-21662

Description

The application does not adequately restrict the types of files that can be uploaded, allowing an attacker to submit files with dangerous content types. Uploaded files may be stored in predictable locations and could be leveraged for further exploitation against the application or its users.

Affected products

1

Patches

Vulnerability mechanics

News mentions

1