Sceawere
Vulnerability Detail
CVE-2026-78414UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Nx Witness VMS Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8
- Creation Date
- 3h ago
- Vendor
- Network Optix
- Product
- Nx Witness VMS
- Attack Type
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary JavaScript in the browser of an authenticated administrator and steal the administrator's session token, resulting in Administrator Account Takeover. An attacker who controls an Nx server on the same network segment can set that server's site name to a script payload, which executes when an administrator opens the "Merge with Another Site" dialog and the site selection list is displayed.Solution: Update to Nx Witness VMS version 6.1.3 or later.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.0",
"pubDate": "2026-08-24T15:16:48.873Z",
"pubdate": "2026-08-24T15:16:48.873Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in the Web Administration interface of Network Optix Nx Witness VMS prior to version 6.1.3 across Linux, Windows, and MacOS platforms.\nThe vulnerability allows an adjacent-network attacker to execute arbitrary JavaScript within the browser context of an authenticated administrator.\nSuccessful exploitation results in the theft of the administrator's session token, leading directly to Administrator Account Takeover.\nThe affected product is Network Optix Nx Witness VMS versions prior to 6.1.3.\nThe primary risk implication is complete administrative compromise of the affected client session and potentially managed infrastructure.\nAttacker capabilities require control of an Nx server located on the same network segment.\nExploitation is contingent upon an authenticated administrator initiating a specific user interface workflow, namely opening the Merge with Another Site dialog where malicious site data is rendered.",
"technicalDetails": "The root cause of the vulnerability is the improper sanitization and output encoding of site names within the Web Administration interface of Network Optix Nx Witness VMS.\nThe vulnerable component is the site selection list displayed within the Merge with Another Site dialog of the administrative web interface.\nAffected versions comprise all instances of Network Optix Nx Witness VMS prior to version 6.1.3 on Linux, Windows, and MacOS operating systems.\nAuthentication requirements dictate that the target must be an authenticated administrator interacting with the administrative web console.\nPrivilege requirements for the victim involve administrator-level access, whereas the attacker requires control of a rogue or compromised Nx server residing on the adjacent network segment.\nNetwork exposure is constrained to the adjacent network where server discovery and site merging procedures take place.\nThe attack flow proceeds as follows: First, an attacker commanding an Nx server on the same network segment configures the rogue server's site name to include a malicious JavaScript payload. Second, an authenticated administrator navigates the Web Administration interface and opens the Merge with Another Site dialog. Third, the application retrieves and renders the site selection list, outputting the unescaped site name containing the script payload into the DOM. Fourth, the arbitrary JavaScript executes within the security context of the administrator's browser session.\nThe payload behavior involves executing arbitrary JavaScript scripts to access local storage, document cookies, or session tokens.\nThe post-exploitation impact is the compromise and theft of the administrator's active session token, enabling the adversary to hijack the administrative session and achieve full Administrator Account Takeover."
}