CVE-2026-21653
HIGH
7.2
CVSS 4.0
Description
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.
This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
Metadata
Severity & Metrics
7.2
HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Johnson Controls | CCure 9000 and victor application server | — | 2.9 ≤ 3.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Victor SSRF |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 7.2 | HIGH | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L |