Server Side Request Forgery Vulnerability in Johnson Controls CCure 9000 and Victor Application Server
CVE-2026-21653

7.2HIGH

What is CVE-2026-21653?

The vulnerability identified in Johnson Controls CCure 9000 and Victor Application Server pertains to Server Side Request Forgery (SSRF), which could allow an attacker to send crafted requests from the application to other internal or external resources, potentially leading to unauthorized access or data leakage. This issue has been observed in CCure 9000 and Victor Application Server, specifically in versions ranging from 2.9 to 3.0. Organizations using these products should take precautionary measures to mitigate risks associated with this vulnerability.

Affected Version(s)

CCure 9000 and victor application server 2.9 <= 3.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.