Low severity2.4NVD Advisory· Published Jul 30, 2026
Johnson Controls OpenBlue Employee
CVE-2026-34495
Description
Stored XSS occurs when the application improperly handles user input and stores malicious JavaScript code within its database. This script is then rendered and executed whenever another user accesses the compromised page. Unlike reflected XSS, persistent XSS is particularly dangerous because the payload remains active until it is manually removed from the system.
Affected products
1Patches
Vulnerability mechanics
News mentions
1- Johnson Controls OpenBlue EmployeeCISA ICS Advisories