Status: UPDATED | Advisory ID: CVE-2026-3014
| CVE | CVE-2026-3014 |
| CVSS Score / Version | 9.1 (Critical) / CVSS v3.1 |
| Updated | 2026-08-11 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Milestone Systems XProtect Management Server, Siemens Siveillance Video V2023 R3, Siemens Siveillance Video V2024 R1, and Siemens Siveillance Video V2025 |
| Classified as | CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Milestone Systems | XProtect Management Server | ||
| Siemens | Siveillance Video V2023 R3 | ||
| Siemens | Siveillance Video V2024 R1 | ||
| Siemens | Siveillance Video V2025 |
| Subsystems | General OT |
| Sectors | Multiple |
Milestone
has released a new version of XProtect® (and several cumulative patch updates)
which fix security vulnerability in Management Server API.
The vulnerability
causes users with edit permissions to the Management Server to be able to
execute arbitrary code in context of the Management Server Service. (NVD)
Monitor Milestone Systems's and Siemens's web pages for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-3014 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-3014 |