CVE-2026-10056: CWE-942: Permissive Cross-Origin Resource Sharing Policy in Network Optix Nx Witness VMS
CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeover via a malicious cross-origin web page visited by the victim. The High security mode is not affected.Workaround: For existing installations running in Standard security mode, set Access-Control-Allow-Credentials to false via the REST API: PATCH /rest/v2/system/settings with body {"supportedOrigins": "null"}. Alternatively, select High security level during initial setup. Solution: Update to Nx Witness VMS version 6.1.2 or later, in which Access-Control-Allow-Credentials is set to false in the default Standard security configuration.
AI Analysis
Technical Summary
This vulnerability arises from a CORS misconfiguration (CWE-942) in the REST API of Network Optix Nx Witness VMS prior to version 6.1.2 when running in Standard security mode on Linux and Windows. The misconfiguration allows an unauthenticated attacker to exploit cross-origin requests to steal session tokens from authenticated users, enabling administrator account takeover. The High security mode does not exhibit this vulnerability. The vendor's fix in version 6.1.2 sets Access-Control-Allow-Credentials to false by default in Standard mode, mitigating the risk. A workaround is available by manually setting this header to false via the REST API.
Potential Impact
Successful exploitation allows an unauthenticated remote attacker to steal session tokens of authenticated users and gain administrator-level control over the Nx Witness VMS system. This compromises confidentiality, integrity, and availability of the system. The vulnerability affects both Linux and Windows deployments running in Standard security mode. High security mode installations are not impacted.
Mitigation Recommendations
A fix is available by updating Nx Witness VMS to version 6.1.2 or later, which corrects the CORS policy by setting Access-Control-Allow-Credentials to false in the default Standard security configuration. For existing installations that cannot immediately update, a workaround is to set Access-Control-Allow-Credentials to false manually via the REST API PATCH /rest/v2/system/settings with the body {"supportedOrigins": "null"}. Alternatively, selecting High security mode during initial setup avoids this vulnerability. No other mitigation steps are indicated by the vendor.
CVE-2026-10056: CWE-942: Permissive Cross-Origin Resource Sharing Policy in Network Optix Nx Witness VMS
Description
CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeover via a malicious cross-origin web page visited by the victim. The High security mode is not affected.Workaround: For existing installations running in Standard security mode, set Access-Control-Allow-Credentials to false via the REST API: PATCH /rest/v2/system/settings with body {"supportedOrigins": "null"}. Alternatively, select High security level during initial setup. Solution: Update to Nx Witness VMS version 6.1.2 or later, in which Access-Control-Allow-Credentials is set to false in the default Standard security configuration.
CVSS v3.1
Score 7.5high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from a CORS misconfiguration (CWE-942) in the REST API of Network Optix Nx Witness VMS prior to version 6.1.2 when running in Standard security mode on Linux and Windows. The misconfiguration allows an unauthenticated attacker to exploit cross-origin requests to steal session tokens from authenticated users, enabling administrator account takeover. The High security mode does not exhibit this vulnerability. The vendor's fix in version 6.1.2 sets Access-Control-Allow-Credentials to false by default in Standard mode, mitigating the risk. A workaround is available by manually setting this header to false via the REST API.
Potential Impact
Successful exploitation allows an unauthenticated remote attacker to steal session tokens of authenticated users and gain administrator-level control over the Nx Witness VMS system. This compromises confidentiality, integrity, and availability of the system. The vulnerability affects both Linux and Windows deployments running in Standard security mode. High security mode installations are not impacted.
Mitigation Recommendations
A fix is available by updating Nx Witness VMS to version 6.1.2 or later, which corrects the CORS policy by setting Access-Control-Allow-Credentials to false in the default Standard security configuration. For existing installations that cannot immediately update, a workaround is to set Access-Control-Allow-Credentials to false manually via the REST API PATCH /rest/v2/system/settings with the body {"supportedOrigins": "null"}. Alternatively, selecting High security mode during initial setup avoids this vulnerability. No other mitigation steps are indicated by the vendor.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- NX
- Date Reserved
- 2026-05-29T07:52:32.185Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a195686e29bf47b50c26982
Added to database: 5/29/2026, 9:04:06 AM
Last enriched: 5/29/2026, 9:19:17 AM
Last updated: 5/29/2026, 5:34:13 PM
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.