Executive brief
A security vulnerability exists in the Johnson Controls CCure 9000 and victor application server, which are systems used for physical security and access control management. An attacker could potentially force the server to make unauthorized requests to internal or external systems, which could lead to the exposure of sensitive information or unauthorized access to internal network resources. This issue affects versions 2.9 through 3.0 of the software.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Victor component of Johnson Controls CCure 9000 and the victor application server. The flaw allows an authenticated attacker with high privileges (PR:H) to submit crafted requests that the server will execute on their behalf. This can be leveraged to interact with internal services that are otherwise unreachable from the external network or to exfiltrate sensitive data. The vulnerability is tracked as CVE-2026-21653 and has been assigned a CVSS 4.0 score of 7.2 by the vendor. Affected versions range from 2.9 to 3.0.
Affected products
- Johnson Controls CCure 9000 2.9 through 3.0
- Johnson Controls victor application server 2.9 through 3.0
Timeline
- 2026-07-23: advisory: NVD and vendor advisory published