CVE-2026-78414
Received Received - Intake

Reflected XSS in Network Optix Nx Witness VMS

Vulnerability report for CVE-2026-78414, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: Network Optix

Description

Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary JavaScript in the browser of an authenticated administrator and steal the administrator's session token, resulting in Administrator Account Takeover. An attacker who controls an Nx server on the same network segment can set that server's site name to a script payload, which executes when an administrator opens the "Merge with Another Site" dialog and the site selection list is displayed.Solution: Update to Nx Witness VMS version 6.1.3 or later.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
network_optix nx_witness_vms From 6.1.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a cross-site scripting (XSS) vulnerability in the Web Administration interface of Network Optix Nx Witness VMS versions before 6.1.3. An attacker on the same network can exploit it by setting a malicious script in a server's site name. When an administrator opens the 'Merge with Another Site' dialog, the script executes in their browser, stealing their session token and allowing full administrative account takeover.

Detection Guidance

Check if your Network Optix Nx Witness VMS version is below 6.1.3. Inspect network traffic for rogue servers with malicious script payloads in their system names. Monitor WebAdmin interface logs for unexpected script execution during 'Merge with Another Site' dialog interactions.

Impact Analysis

An attacker could gain full administrative access to your Network Optix Nx Witness VMS without needing credentials. This could allow them to view, modify, or delete sensitive video feeds, user accounts, and system configurations. The attack requires the attacker to be on the same network segment as your system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating privacy regulations like GDPR and HIPAA. Unauthorized administrative access may result in data breaches, non-compliance with data protection requirements, and potential legal consequences for organizations handling protected information.

Mitigation Strategies

Immediately update Network Optix Nx Witness VMS to version 6.1.3 or later. Ensure no rogue servers with malicious system names are present on the network. Verify that HTML entity encoding is applied to external server metadata in the WebAdmin interface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78414. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart