← All Advisories

CVE-2026-3014

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-3014

Key Details

CVECVE-2026-3014
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-08-11
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsMilestone Systems XProtect Management Server, Siemens Siveillance Video V2023 R3, Siemens Siveillance Video V2024 R1, and Siemens Siveillance Video V2025
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Milestone SystemsXProtect Management Server
SiemensSiveillance Video V2023 R3
SiemensSiveillance Video V2024 R1
SiemensSiveillance Video V2025
SubsystemsGeneral OT
SectorsMultiple

What to Know

Milestone

has released a new version of XProtect® (and several cumulative patch updates)

which fix security vulnerability in Management Server API.

The vulnerability

causes users with edit permissions to the Management Server to be able to

execute arbitrary code in context of the Management Server Service. (NVD)

What to Do

Monitor Milestone Systems's and Siemens's web pages for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-3014
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-3014