CVE-2026-78414
8.0Network Optix · Nx Witness VMS
A cross-site scripting vulnerability in the Network Optix Nx Witness VMS web administration interface allows for malicious script execution.
Executive summary
A cross-site scripting vulnerability in the Network Optix Nx Witness VMS web administration interface could allow an attacker to compromise user sessions and perform unauthorized actions.
Vulnerability
This is a cross-site scripting (XSS) vulnerability residing in the web administration interface. It occurs due to improper neutralization of input during web page generation, allowing a remote attacker to inject malicious scripts.
Business impact
The vulnerability has a CVSS score of 8.0, indicating a high level of risk. Successful exploitation could allow an attacker to steal session cookies, hijack administrative accounts, or perform actions on behalf of authenticated users, significantly impacting the integrity and security of the video management system.
Remediation
Immediate Action: Update the Nx Witness VMS software to version 6.1.3 or later as recommended by the vendor.
Proactive Monitoring: Monitor logs for suspicious URL parameters or input strings that resemble script injection attempts within the administrative interface.
Compensating Controls: Ensure that users are educated on the risks of clicking suspicious links and utilize browser-based security features to mitigate XSS risks where possible.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Administrators should prioritize the update to Nx Witness VMS version 6.1.3 to remediate the XSS vulnerability. Timely patching is essential to prevent session hijacking and unauthorized control over the VMS platform.