Home Network Optix CVE-2026-10056
Back to Network Optix

CVE-2026-10056

Network Optix Nx Witness VMS - REST API

Network Optix CVSS 7.5 Updated May 29, 2026

Executive Risk Summary

"A CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2 allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeover. This vulnerability can be exploited via a malicious cross-origin web page visited by the victim, but only when the system is running in the default Standard security mode."

Anticipated Attack Path

  1. 1. Attacker creates a malicious cross-origin web page
  2. 2. Victim visits the malicious web page while authenticated to the Nx Witness VMS
  3. 3. Attacker steals the session token and performs Administrator Account Takeover

Am I Vulnerable?

  • Verify the Nx Witness VMS version is 6.1.2 or later
  • Check the Access-Control-Allow-Credentials setting via the REST API
  • Consider setting the security level to High during initial setup

Operational Audit Arsenal

Target Type REST API
Target Asset Nx Witness VMS REST API
Standard Path https://support.networkoptix.com/hc/en-us/articles/39254208939159

Manual Verification Required

This is a non-Windows asset (Network Optix). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Unlikely

Minimal, as the update only changes the default Standard security configuration

Internal Work Notes

CVE-2026-10056: CORS misconfiguration in Nx Witness VMS REST API allows unauthenticated remote attacker to steal session token and perform Administrator Account Takeover. Update to version 6.1.2 or later to fix the issue.

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.