---
id: CVE-2026-3014
title: |-
  Milestone
  has released a new version of XProtect® (and several cumulative patch updates)
  which fix security vulnerability in Management Server API.



  The vulnerability
  causes users with edit permissions to the Management Server to be ab…
summary: |-
  Milestone
  has released a new version of XProtect® (and several cumulative patch updates)
  which fix security vulnerability in Management Server API.



  The vulnerability
  causes users with edit permissions to the Management Server to be ab…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2026-07-14'
updated: '2026-07-16'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3014'
references:
  - url: >-
      https://doc.milestonesys.com/en-US/bundle/sec1504_latest/page/milestone_security_advisory_CVE-2026-3014_potential_remote_code_execution_by_admin_user_on_Management_Server.html
    label: cf45122d-9d50-442a-9b23-e05cde9943d8
  - url: >-
      https://support.milestonesys.com/article/CVE-2026-3014-potential-remote-code-execution-by-admin-user-on-Management-Server
    label: cf45122d-9d50-442a-9b23-e05cde9943d8
tags:
  - nvd
epss: 0.00782
epssPercentile: 0.54512
ingestedAt: '2026-07-17T13:12:08.401Z'
---

## Overview

Milestone
has released a new version of XProtect® (and several cumulative patch updates)
which fix security vulnerability in Management Server API.



The vulnerability
causes users with edit permissions to the Management Server to be able to
execute arbitrary code in context of the Management Server Service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
