Junglewise Threat Intelligence

CVE-2026-55730: Loytec LWEB-802 reflected cross-site scripting in LWEB802

CVE-2026-55730 · Severity: info · CVSS 8.7 · Published 2026-07-24

Vendors: LOYTEC.

Executive brief

Loytec LWEB-802, a building management and automation software, is vulnerable to a security flaw that allows attackers to run malicious code in a user's web browser. By tricking a user into clicking a specially crafted link, an attacker can hijack the user's session, perform unauthorized actions with their privileges, or steal sensitive information. This could lead to unauthorized access to building control systems or data exposure.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the LWEB802 component of Loytec LWEB-802. The root cause is improper neutralization of input during web page generation (CWE-79) and improper encoding of output (CWE-116) within the 'project' and 'mspParams' parameters. An unauthenticated remote attacker can exploit this by sending a crafted URL to a victim. If the victim visits the link, the attacker's JavaScript executes within the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The vulnerability is addressed in version 5.0.8.

Affected products

  • Loytec LWEB-802 before 5.0.8

Timeline

  • 2026-07-24: advisory: NVD and vendor advisory published
  • 2026-07-24: patched: Fix released in version 5.0.8

References

Related threats