CVE-2026-10056
Last modified
CVE-2026-10056 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeover via a malicious cross-origin web page visited by the victim. The High security mode is not affected.Workaround: For existing installations running in Standard security mode, set Access-Control-Allow-Credentials to false via the REST API: PATCH /rest/v2/system/settings with body {"supportedOrigins": "null"}. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeover via a malicious cross-origin web page visited by the victim. The High security mode is not affected.Workaround: For existing installations running in Standard security mode, set Access-Control-Allow-Credentials to false via the REST API: PATCH /rest/v2/system/settings with body {"supportedOrigins": "null"}. Alternatively, select High security level during initial setup. Solution: Update to Nx Witness VMS version 6.1.2 or later, in which Access-Control-Allow-Credentials is set to false in the default Standard security configuration.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Network Optix | Nx Witness VMS | < 6.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-10056?
How severe is CVE-2026-10056?
How do I fix CVE-2026-10056?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1005Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows …5.3
- CVE-2026-10050In Eclipse Jetty, the Digest authentication server-side comp…9.1
- CVE-2026-10051In Eclipse Jetty, a first HTTP/1.1 request with trailers cau…7.5
- CVE-2026-10052A flaw was found in the Quay config-tool's LDAP and SMTP val…4.1
- CVE-2026-10054In affected versions of Eclipse Theia (1.8.1 and later), the…8.8
- CVE-2026-10055In Eclipse Theia since version 1.26.0, the backend /services…8.5
- CVE-2026-10057ITS Intelligent SCADA System developed by ITP Technology has…4.8
- CVE-2026-10058ITS Intelligent SCADA System developed by ITP Technology has…4.8
- CVE-2026-10059A flaw was found in the Multicluster Engine for Kubernetes C…9.1
- CVE-2026-10060A vulnerability has been found in TRENDnet TEW-432BRP 3.10B2…9.8
- CVE-2026-10061A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Af…9.8
- CVE-2026-10062A vulnerability was determined in TRENDnet TEW-432BRP 3.10B2…9.8
Are you affected by CVE-2026-10056?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
