CVE-2026-21655
Johnson Controls · victor
A deserialization of untrusted data vulnerability in Johnson Controls victor allows an unauthenticated attacker to compromise system integrity.
Executive summary
A critical deserialization vulnerability in Johnson Controls victor software, rated at 8.7 on the CVSS scale, poses a significant risk of unauthorized system impact.
Vulnerability
This vulnerability involves the insecure deserialization of untrusted data, which can lead to arbitrary code execution or significant system disruption. The vulnerability is exploitable by an unauthenticated attacker over the adjacent network (AV:A), requiring no specific user interaction.
Business impact
The exploitation of this flaw allows an attacker to achieve high levels of impact across confidentiality, integrity, and availability. Given the 8.7 CVSS score, this represents a major security risk that could lead to unauthorized control over security infrastructure managed by the victor platform. Organizations using this software face potential service outages and loss of control over physical security systems.
Remediation
Immediate Action: Upgrade to version 3.0 or the latest available release provided by Johnson Controls to remediate the deserialization flaw.
Proactive Monitoring: Monitor network traffic for unusual patterns originating from adjacent network segments and review application logs for unexpected system behavior or crashes.
Compensating Controls: Implement network segmentation to restrict access to the victor management interface to trusted hosts only, thereby reducing the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This high-severity vulnerability requires immediate attention due to the ease of exploitation for attackers on the local network. Administrators should prioritize upgrading the victor software to the patched version to neutralize the threat of arbitrary data processing.