๐Ÿ” CVE Alert

CVE-2026-58113

MEDIUM 6.1
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.

CWE CWE-79
Vendor siemens
Product teamcenter v2412
Ecosystems
Industries
IndustrialManufacturing
Published Sep 8, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for siemens teamcenter v2412

Be the first to know when new medium vulnerabilities affecting siemens teamcenter v2412 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Siemens / Teamcenter V2412
0 < V2412.0013
Siemens / Teamcenter V2506
0 < V2506.0010
Siemens / Teamcenter V2512
0 < V2512.2607
Siemens / Teamcenter V2606
0 < V2606.2607

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
cert-portal.siemens.com: https://cert-portal.siemens.com/productcert/html/ssa-157465.html