CVE-2026-3014 -- CVSS 9.1 Vulnerability Briefing
CVE-2026-3014 | CVSS 9.1 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-3014 is a privilege escalation or unauthorized access vulnerability in the Management Server API component of Milestone XProtect, a widely deployed video management software platform.
Technical Detail
The flaw resides in the Management Server API and is triggered by users who hold edit permissions within the XProtect environment. Based on the available description, the vulnerability allows a user with limited edit-level access to perform actions or access resources beyond their intended authorization scope, likely constituting a privilege escalation or authorization bypass. The full technical mechanism and maximum impact boundary have not been publicly disclosed by Milestone, but the CVSS score of 9.1 indicates high impact to confidentiality, integrity, or availability with low attack complexity.
Exploitation Status
No known exploit exists for this vulnerability at this time. It is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploit maturity is assessed as none, meaning no public proof-of-concept or observed in-the-wild exploitation has been confirmed as of July 21, 2026.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE in available intelligence sources.
What To Do
Apply the latest version of Milestone XProtect and all associated cumulative patch updates released by Milestone to address this vulnerability. Organizations should prioritize patching any internet-exposed or network-accessible Management Server instances first. As an interim measure, restrict API access to the Management Server to trusted internal networks and enforce the principle of least privilege on all XProtect user accounts, particularly those with edit permissions. Monitor Management Server API logs for anomalous permission usage or unexpected administrative actions. Consult Milestone's official security advisory for specific version numbers and patch availability.