CVE-2026-4293
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
May 20, 2026
Vendor
unknown
Description
The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser.