CVE-2026-78414: Cross-site scripting in Nx Witness VMS Web Administration allows session token exfiltration via a rogue peer site name

Published Aug 24, 2026
·
Updated

Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary JavaScript in the browser of an authenticated administrator and steal the administrator's session token, resulting in Administrator Account Takeover. An attacker who controls an Nx server on the same network segment can set that server's site name to a script payload, which executes when an administrator opens the "Merge with Another Site" dialog and the site selection list is displayed.Solution:

Update to Nx Witness VMS version 6.1.3 or later.

Affected Software

1 affected component
Network Optix Nx Witness VMS<6.1.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Network Optix Nx Witness VMS Web Administration to a version that resolves this vulnerability.

    Fixed in 6.1.3

Event History

Aug 24, 2026
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which environments are exposed to this issue?

Nx Witness VMS deployments before version 6.1.3 on Linux, Windows, and macOS are affected. Exploitation requires an attacker-controlled Nx server on the same network segment as the targeted environment.

2

What user action is required for exploitation?

An authenticated administrator must open the "Merge with Another Site" dialog and display the site selection list. The rogue server's site name can then cause attacker-supplied JavaScript to execute in the administrator's browser.

3

What access does an attacker need?

The attacker does not need credentials, but must be able to control an Nx server on the same network segment and set its site name to a script payload. Successful exploitation targets an authenticated administrator's browser session.

4

What is the impact of a successful attack?

The attacker can steal the administrator's session token and take over the administrator account. The vulnerability is rated high and can affect confidentiality, integrity, and availability.

5

What should be done if the system cannot be updated immediately?

The provided remediation is to update Nx Witness VMS to version 6.1.3 or later. Until updating, avoid opening the "Merge with Another Site" dialog where untrusted or rogue peer sites may appear.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203