Description
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586.

This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.
Published: 2026-07-23
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a deserialization flaw (CWE-502) that occurs in Johnson Controls products when they accept serialized data from untrusted sources. An attacker can supply crafted objects to the Victor server on Windows, the CCure 9000 platform, or the Victor Application Server, potentially allowing execution of arbitrary code or other serious compromise of confidentiality, integrity, or availability. The weakness conforms to Capec-586 and is described as enabling unauthorized deserialization of data.

Affected Systems

Johnson Controls Victor server on Windows is vulnerable in all releases before version 8.0. The CCure 9000 platform is affected in installations earlier than 3.2. The Victor Application Server is impacted for versions earlier than 4.1. These products are affected by the deserialization of untrusted data flaw.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability, and although the EPSS score is less than 1% (suggesting a low probability of exploitation, it is not zero). The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker who can supply or inject serialized objects to the server, possibly via HTTP or another interface, to trigger the flaw.

Generated by OpenCVE AI on August 7, 2026 at 01:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Victor server to version 8.0 or later, CCure 9000 to version 3.2 or later, and the Victor Application Server to version 4.1 or later, to eliminate the exposed deserialization code.
  • If the source of serialized data cannot be fully controlled, block or filter requests that carry suspicious serialization patterns at the network perimeter.
  • Implement strict input validation on all endpoints that accept serialized input, ensuring only trusted or properly formatted data is processed, thereby mitigating CWE‑502.

Generated by OpenCVE AI on August 7, 2026 at 01:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0. Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.
First Time appeared Johnson Controls
Johnson Controls ccure 9000
Johnson Controls victor Application Server
CPEs cpe:2.3:a:johnson_controls:ccure_9000:*:*:*:*:*:*:*:*
cpe:2.3:a:johnson_controls:victor_application_server:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls ccure 9000
Johnson Controls victor Application Server

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Johnsoncontrols
Johnsoncontrols victor
Vendors & Products Johnsoncontrols
Johnsoncontrols victor

Sat, 25 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.
Title C-CURE 9000 and Victor application server - Deserialization of Untrusted Data
First Time appeared Johnson Control
Johnson Control victor
Weaknesses CWE-502
CPEs cpe:2.3:a:johnson_control:victor:*:*:windows:*:*:*:*:*
Vendors & Products Johnson Control
Johnson Control victor
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Johnson Control Victor
Johnson Controls Ccure 9000 Victor Application Server
Johnsoncontrols Victor
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-08-06T17:49:48.709Z

Reserved: 2026-01-02T13:23:28.169Z

Link: CVE-2026-21655

cve-icon Vulnrichment

Updated: 2026-07-24T13:34:42.465Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-23T21:17:03.810

Modified: 2026-08-06T22:17:00.500

Link: CVE-2026-21655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:45:05Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data