Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586.

This issue affects victor: from 2.9 before 3.0.

Project Subscriptions

Vendors Products
Johnson Control Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.
Title C-CURE 9000 and Victor application server - Deserialization of Untrusted Data
First Time appeared Johnson Control
Johnson Control victor
Weaknesses CWE-502
CPEs cpe:2.3:a:johnson_control:victor:*:*:windows:*:*:*:*:*
Vendors & Products Johnson Control
Johnson Control victor
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-07-24T13:34:45.585Z

Reserved: 2026-01-02T13:23:28.169Z

Link: CVE-2026-21655

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses