CVE-2026-21653
HIGH
7.2
CVSS 4.0
Description
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.
This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
Metadata
Severity & Metrics
7.2
HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Johnson Controls | CCure 9000 and victor application server | — | 2.9 ≤ 3.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Victor SSRF |
| CWE-918 | adp | CWE-918 Server-Side Request Forgery (SSRF) |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 7.2 | HIGH | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L |