{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-3014","assignerOrgId":"cf45122d-9d50-442a-9b23-e05cde9943d8","state":"PUBLISHED","assignerShortName":"Milestone","dateReserved":"2026-02-23T09:28:18.635Z","datePublished":"2026-07-14T09:45:22.651Z","dateUpdated":"2026-07-16T12:40:32.623Z"},"containers":{"cna":{"providerMetadata":{"orgId":"cf45122d-9d50-442a-9b23-e05cde9943d8","shortName":"Milestone","dateUpdated":"2026-07-16T12:40:32.623Z"},"title":"Remote Code Execution by administrative user on the Management Server","datePublic":"2026-07-14T10:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-78","description":"CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-248","descriptions":[{"lang":"en","value":"CAPEC-248 Command Injection"}]}],"affected":[{"vendor":"Milestone Systems","product":"XProtect Management Server","versions":[{"status":"affected","version":"0","lessThanOrEqual":"25.3","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Milestone\nhas released a new version of XProtect® (and several cumulative patch updates)\nwhich fix security vulnerability in Management Server API.\n\n\n\nThe vulnerability\ncauses users with edit permissions to the Management Server to be able to\nexecute arbitrary code in context of the Management Server Service.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>Milestone\nhas released a new version of XProtect® (and several cumulative patch updates)\nwhich fix security vulnerability in Management Server API.</p><p>The vulnerability\ncauses users with edit permissions to the Management Server to be able to\nexecute arbitrary code in context of the Management Server Service.&nbsp;&nbsp;</p>"}]}],"references":[{"url":"https://support.milestonesys.com/article/CVE-2026-3014-potential-remote-code-execution-by-admin-user-on-Management-Server","tags":["permissions-required"]},{"url":"https://doc.milestonesys.com/en-US/bundle/sec1504_latest/page/milestone_security_advisory_CVE-2026-3014_potential_remote_code_execution_by_admin_user_on_Management_Server.html","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","subConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","subIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":6.4,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"CRITICAL","baseScore":9.1,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"}}],"solutions":[{"lang":"en","value":"To\nmitigate the issue, we highly recommend upgrading to the latest version of\nXProtect VMS. For versions 2023 R3 – 2025 R3, please use the\nprovided cumulative patches. \n\n\n\nThe affected components that need to be patched are\nXProtect Management Server, XProtect Recording Server and XProtect Management\nClient.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>To\nmitigate the issue, we highly recommend upgrading to the latest version of\nXProtect VMS. For versions 2023 R3 – 2025 R3, please use the\nprovided cumulative patches.&nbsp;</p><p>The affected components that need to be patched are\nXProtect Management Server, XProtect Recording Server and XProtect Management\nClient.</p>"}]}],"credits":[{"lang":"en","value":"Icare","type":"finder"},{"lang":"en","value":"Zyp3","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.2"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-14T12:08:38.312691Z","id":"CVE-2026-3014","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-14T12:08:51.992Z"}}]}}