VYPR
Low severity2.4NVD Advisory· Published Jul 30, 2026

Johnson Controls OpenBlue Employee

CVE-2026-34495

Description

Stored XSS occurs when the application improperly handles user input and stores malicious JavaScript code within its database. This script is then rendered and executed whenever another user accesses the compromised page. Unlike reflected XSS, persistent XSS is particularly dangerous because the payload remains active until it is manually removed from the system.

Affected products

1

Patches

Vulnerability mechanics

News mentions

1
CVE-2026-34495 · low · VYPR