← Back to CVE search

CVE-2026-3014

XProtect

Description

Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service.

CVSS 9.1EPSS 0.47600000000000003%Risk 0.95
View source
Published
2026-07-14 10:16:32
Affected versions
unknown
Type
Critical software
Last modified
2026-08-11 13:18:47
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H