Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management Server to have full read/write access to MIP Webhooks API.
Advisories

No advisories yet.

Fixes

Solution

To mitigate the issue, we highly recommend upgrading to the latest version of XProtect VMS, or at least to version 2025 R2 or later. The other option (for versions 2023 R1 – 2025 R1) is to use the provided cumulative patches (Knowledee Base article no. 34370 XProtect VMS cumulative patches). If, for any reason it is not possible, we recommend auditing your role security settings and considering everyone with read-only access to the Management Server as having a full access to Webhooks configuration.


Workaround

No workaround given by the vendor.

History

Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Milestone Systems
Milestone Systems xprotect Vms
Vendors & Products Milestone Systems
Milestone Systems xprotect Vms

Tue, 16 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 14:30:00 +0000


Tue, 16 Dec 2025 13:45:00 +0000


Tue, 16 Dec 2025 11:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management Server to have full read/write access to MIP Webhooks API.
Title XProtect MIP API Missing Authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Milestone

Published:

Updated: 2025-12-16T14:51:38.048Z

Reserved: 2025-01-29T13:24:34.734Z

Link: CVE-2025-0836

cve-icon Vulnrichment

Updated: 2025-12-16T14:51:33.939Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-16T11:15:43.510

Modified: 2025-12-16T14:15:45.630

Link: CVE-2025-0836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-16T17:09:22Z

Weaknesses