← Back to CVE List
CVE-2026-21653NVD
Vulnerability Summary
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.
This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
CVSS v4.0 Base Metrics — Score 7.2 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredHigh
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)Low
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)High
Integrity (Subsequent System)High
Availability (Subsequent System)Low
Affected & Patched Versions
- Johnson Controls CCure 9000 and victor application server >= 2.9 and <= 3.0
- Johnson Controls CCure 9000 and victor application server 3.0