Skip to content
SiemensCVE-2026-58113

Siemens Teamcenter: cross-site scripting

High8.5CVE-2026-58113 · Published Sep 8, 2026 · updated Sep 9, 2026

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.

Siemens advisory

Affected versions

PackageAffectedFixed in
Teamcenter V2412
Product
< V2412.0013V2412.0013
Teamcenter V2506
Product
< V2506.0010V2506.0010
Teamcenter V2512
Product
< V2512.2607V2512.2607
Teamcenter V2606
Product
< V2606.2607V2606.2607
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-79

More Siemens advisories

All Siemens
Advisory
Siemens SIMOVE Fleetmanager: path traversal
Critical9.2Sep 8
Siemens Reyrolle 7SR5: denial of service
High8.7Sep 8
Siemens Reyrolle 7SR5: improper access control
High8.7Sep 8
Siemens Reyrolle 7SR5: unauthenticated attacker could the publicly available
Medium6.9Sep 8
Siemens Reyrolle 7SR5: memory corruption
High7.0Sep 8
Siemens Reyrolle 7SR5: attacker could the device to upload
High7.0Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.