Unrated severityNVD Advisory· Published Jul 14, 2026· Updated Jul 16, 2026
Remote Code Execution by administrative user on the Management Server
CVE-2026-3014
Description
Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API.
The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service.
Affected products
1Patches
Vulnerability mechanics
References
2- doc.milestonesys.com/en-US/bundle/sec1504_latest/page/milestone_security_advisory_CVE-2026-3014_potential_remote_code_execution_by_admin_user_on_Management_Server.htmlmitrevendor-advisory
- support.milestonesys.com/article/CVE-2026-3014-potential-remote-code-execution-by-admin-user-on-Management-Servermitrepermissions-required
News mentions
0No linked articles in our index yet.