Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Johnsoncontrols
Johnsoncontrols ccure 9000 And Victor Application Server
Vendors & Products Johnsoncontrols
Johnsoncontrols ccure 9000 And Victor Application Server

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
Title CCure and Victor Application Server - Server Side Request Forgery
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published: 2026-07-23T20:19:32.586Z

Updated: 2026-07-24T13:35:30.721Z

Reserved: 2026-01-02T13:23:28.168Z

Link: CVE-2026-21653

cve-icon Vulnrichment

Updated: 2026-07-24T13:35:26.851Z

cve-icon NVD

No data.

cve-icon Redhat

No data.