Description
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.

This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
Published: 2026-07-23
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Server Side Request Forgery (SSRF) flaw that allows an attacker to instruct the vulnerable application to make arbitrary HTTP requests to internal or external systems. An exploited SSRF can enable information disclosure, internal network reconnaissance, or further lateral movement, potentially affecting the confidentiality and integrity of internal resources. The CVSS score of 7.2 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present, yet the existence of the flaw warrants remediation.

Affected Systems

Johnson Controls CCure 9000 and Victor application server, versions 2.9 through 3.0, are affected by this SSRF vulnerability.

Risk and Exploitability

The CVSS score of 7.2 reflects a significant risk if the flaw is exploitable. The EPSS score of < 1% and absence of listing in CISA KEV indicate that, while exploitation is currently unlikely, the vulnerability remains a potential threat. The description does not detail authentication requirements; however, the typical SSRF attack vector is inferred to be an accessible endpoint allowing an attacker to craft requests, thereby forcing the server to reach arbitrary URLs, including internal resources. No official workaround is provided by the vendor.

Generated by OpenCVE AI on August 3, 2026 at 20:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-supplied patch or upgrade to a fixed version as soon as it becomes available.
  • Restrict outbound network connectivity from the affected application servers, allowing only necessary destinations.
  • Implement network segmentation and firewalling to limit the reach of any forged requests to sensitive internal resources.

Generated by OpenCVE AI on August 3, 2026 at 20:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Johnsoncontrols
Johnsoncontrols ccure 9000 And Victor Application Server
Vendors & Products Johnsoncontrols
Johnsoncontrols ccure 9000 And Victor Application Server

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
Title CCure and Victor Application Server - Server Side Request Forgery
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L'}


Subscriptions

Johnsoncontrols Ccure 9000 And Victor Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-07-24T13:35:30.721Z

Reserved: 2026-01-02T13:23:28.168Z

Link: CVE-2026-21653

cve-icon Vulnrichment

Updated: 2026-07-24T13:35:26.851Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-23T21:17:03.653

Modified: 2026-07-30T14:15:31.167

Link: CVE-2026-21653

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)