Cross-Site Scripting Vulnerability in Johnson Controls Product
CVE-2026-71454
5.8MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-71454?
A vulnerability exists in Johnson Controls' web page generation software that allows improper neutralization of user input, leading to potential Cross-Site Scripting (XSS) attacks. Attackers could exploit this flaw to execute arbitrary scripts in the context of a user's browser session, compromising sensitive information and promoting malicious activities. It is essential for users of the affected software version to implement necessary mitigation strategies to safeguard against these security risks.
Affected Version(s)
CAPEC-63 0 < 3.0b63
References
CVSS V4
Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gabriele Gardois, Zachary Bushell and Lorenzo De Carli
