Finding
indicator:29290:descriptionWhat happened
NVD describes CVE-2026-4293 as: The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser.