High severity8.0NVD Advisory· Published Jul 23, 2026
Johnson Controls C-CURE 9000 and Victor application server
CVE-2026-34496
Description
Under certain circumstances, successful exploitation of this vulnerability could result in low privilege users accessing unauthorized pages such as Users and Logs. Successful exploitation could allow an attacker to view sensitive system information, user account details, and audit logs beyond their intended access level, potentially enabling further attacks or unauthorized administrative actions.
Affected products
2Patches
Vulnerability mechanics
News mentions
1- Johnson Controls C-CURE 9000 and Victor application serverCISA ICS Advisories