VYPR
High severity8.0NVD Advisory· Published Jul 23, 2026

Johnson Controls C-CURE 9000 and Victor application server

CVE-2026-34496

Description

Under certain circumstances, successful exploitation of this vulnerability could result in low privilege users accessing unauthorized pages such as Users and Logs. Successful exploitation could allow an attacker to view sensitive system information, user account details, and audit logs beyond their intended access level, potentially enabling further attacks or unauthorized administrative actions.

Affected products

2

Patches

Vulnerability mechanics

News mentions

1