VYPR
Low severity2.4NVD Advisory· Published Jul 30, 2026

Johnson Controls OpenBlue Employee

CVE-2026-34497

Description

HTML injection occurs when user-controlled input is embedded into web pages without proper encoding or sanitization, allowing attackers to inject arbitrary HTML markup. This vulnerability enables attackers to manipulate the Document Object Model (DOM) structure and alter the visual presentation of web content. Unlike Cross-Site Scripting (XSS), HTML injection typically involves static HTML content rather than executable JavaScript, though it can serve as a stepping stone to more severe attacks.

Affected products

1

Patches

Vulnerability mechanics

News mentions

1