Cross-Site Scripting in Network Optix Nx Witness VMS on Multiple Platforms
CVE-2026-78414
8HIGH
What is CVE-2026-78414?
A vulnerability exists in the Web Administration interface of Network Optix Nx Witness VMS, allowing adjacent-network attackers to exploit Cross-Site Scripting. By executing arbitrary JavaScript, an attacker can steal an authenticated administrator's session token. This occurs when an administrator opens the 'Merge with Another Site' dialog, where a controlled Nx server can inject a malicious script through its site name. Users are advised to upgrade to version 6.1.3 or later to mitigate this risk.
Affected Version(s)
Nx Witness VMS Linux 0 < 6.1.3
