Description
Milestone
has released a new version of XProtect® (and several cumulative patch updates)
which fix security vulnerability in Management Server API.



The vulnerability
causes users with edit permissions to the Management Server to be able to
execute arbitrary code in context of the Management Server Service.
Published: 2026-07-14
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Management Server API permits a user with edit permissions to run arbitrary code within the context of the Management Server Service. This results in remote code execution, granting full control over the server’s processes and data, compromising confidentiality, integrity, and availability. The weakness is a classic command‑in‑jection issue classified as CWE‑78.

Affected Systems

Milestone Systems XProtect Management Server, as well as the XProtect Recording Server and XProtect Management Client, are vulnerable. The advisory recommends applying the latest cumulative patches that address this issue for all supported releases from 2023 R3 to 2025 R3.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity, while an EPSS score of less than 1 % means the likelihood of exploitation is low at present. The vulnerability can be leveraged only by users who already possess edit permissions on the Management Server, so restricting those rights mitigates risk. Because the issue is not listed in KEV, there no known active exploitation in the wild, but the possible remote code execution warrants caution.

Generated by OpenCVE AI on July 31, 2026 at 10:34 UTC.

Remediation

Vendor Solution

To mitigate the issue, we highly recommend upgrading to the latest version of XProtect VMS. For versions 2023 R3 – 2025 R3, please use the provided cumulative patches.  The affected components that need to be patched are XProtect Management Server, XProtect Recording Server and XProtect Management Client.


OpenCVE Recommended Actions

  • Upgrade XProtect VMS to the latest version or apply the cumulative patches for 2023 R3–2025 R3.
  • Patch all affected components – XProtect Management Server, XProtect Recording Server, and XProtect Management Client.
  • Restrict edit permissions to trusted administrators and audit permissions regularly to ensure only authorized users retain elevated access.

Generated by OpenCVE AI on July 31, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Milestone Systems
Milestone Systems xprotect Management Server
Vendors & Products Milestone Systems
Milestone Systems xprotect Management Server

Thu, 16 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API.  The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service. Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service.

Wed, 15 Jul 2026 13:30:00 +0000


Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API.  The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service.
Title Remote Code Execution by administrative user on the Management Server
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H'}


Subscriptions

Milestone Systems Xprotect Management Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Milestone

Published:

Updated: 2026-07-16T12:40:32.623Z

Reserved: 2026-02-23T09:28:18.635Z

Link: CVE-2026-3014

cve-icon Vulnrichment

Updated: 2026-07-14T12:08:46.628Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:45:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')