Remote Code Execution by administrative user on the Management Server
Summary
| CVE | CVE-2026-3014 |
|---|---|
| State | PUBLISHED |
| Assigner | Milestone |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-14 10:16:32 UTC |
| Updated | 2026-07-16 13:16:31 UTC |
| Description | Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service. |
Risk And Classification
Primary CVSS: v4.0 6.4 MEDIUM from cf45122d-9d50-442a-9b23-e05cde9943d8
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.006470000 probability, percentile 0.469750000 (date 2026-07-20)
Problem Types: CWE-78 | CWE-78 CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | cf45122d-9d50-442a-9b23-e05cde9943d8 | Secondary | 6.4 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/C... |
| 4.0 | CNA | CVSS | 6.4 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H |
| 3.1 | cf45122d-9d50-442a-9b23-e05cde9943d8 | Secondary | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Milestone Systems | XProtect Management Server | affected 25.3 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.milestonesys.com/article/CVE-2026-3014-potential-remote-code-execution-by-admi... | cf45122d-9d50-442a-9b23-e05cde9943d8 | support.milestonesys.com | |
| doc.milestonesys.com/en-US/bundle/sec1504_latest/page/milestone_security_advisory_... | cf45122d-9d50-442a-9b23-e05cde9943d8 | doc.milestonesys.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Icare (en)
CNA: Zyp3 (en)
Additional Advisory Data
Solutions
CNA: To mitigate the issue, we highly recommend upgrading to the latest version of XProtect VMS. For versions 2023 R3 – 2025 R3, please use the provided cumulative patches. The affected components that need to be patched are XProtect Management Server, XProtect Recording Server and XProtect Management Client.