CVE-2026-78414: Cross-site scripting in Nx Witness VMS Web Administration allows session token exfiltration via a rogue peer site name
Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary JavaScript in the browser of an authenticated administrator and steal the administrator's session token, resulting in Administrator Account Takeover. An attacker who controls an Nx server on the same network segment can set that server's site name to a script payload, which executes when an administrator opens the "Merge with Another Site" dialog and the site selection list is displayed.Solution:
Update to Nx Witness VMS version 6.1.3 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Network Optix Nx Witness VMS Web Administrationto a version that resolves this vulnerability.Fixed in 6.1.3
Event History
Frequently Asked Questions
Which environments are exposed to this issue?
Nx Witness VMS deployments before version 6.1.3 on Linux, Windows, and macOS are affected. Exploitation requires an attacker-controlled Nx server on the same network segment as the targeted environment.
What user action is required for exploitation?
An authenticated administrator must open the "Merge with Another Site" dialog and display the site selection list. The rogue server's site name can then cause attacker-supplied JavaScript to execute in the administrator's browser.
What access does an attacker need?
The attacker does not need credentials, but must be able to control an Nx server on the same network segment and set its site name to a script payload. Successful exploitation targets an authenticated administrator's browser session.
What is the impact of a successful attack?
The attacker can steal the administrator's session token and take over the administrator account. The vulnerability is rated high and can affect confidentiality, integrity, and availability.
What should be done if the system cannot be updated immediately?
The provided remediation is to update Nx Witness VMS to version 6.1.3 or later. Until updating, avoid opening the "Merge with Another Site" dialog where untrusted or rogue peer sites may appear.