CVE-2026-3014
CRITICALRemote Code Execution by administrative user on the Management Server
Title source: cnaDescription
Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service.
References (2)
Core 2
Core References
Scores
CVSS v3
9.1
EPSS
0.0048
EPSS Percentile
38.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
Milestone Systems/XProtect Management Server
< 25.3
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026