Low severity2.4NVD Advisory· Published Jul 30, 2026
Johnson Controls OpenBlue Employee
CVE-2026-34497
Description
HTML injection occurs when user-controlled input is embedded into web pages without proper encoding or sanitization, allowing attackers to inject arbitrary HTML markup. This vulnerability enables attackers to manipulate the Document Object Model (DOM) structure and alter the visual presentation of web content. Unlike Cross-Site Scripting (XSS), HTML injection typically involves static HTML content rather than executable JavaScript, though it can serve as a stepping stone to more severe attacks.
Affected products
1Patches
Vulnerability mechanics
News mentions
1- Johnson Controls OpenBlue EmployeeCISA ICS Advisories