CVE-2026-4293
20.05.2026, 16:16
The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser.
Awaiting analysis
This vulnerability is currently awaiting analysis.