PT-2026-64165 · Victor · Victor

CVE-2026-21655

·

Published

2026-07-23

·

Updated

2026-08-06

CVSS v4.0

8.7

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions victor versions 2.9 through 2.9
Description An issue exists in the Windows version of the software where the deserialization of untrusted data allows for CAPEC-586, which refers to the process of converting data from a stream or file back into an object in a way that can be manipulated by an attacker to execute unauthorized code or actions.
Recommendations Update victor to version 3.0.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21655

Affected Products

Victor