Vulnerability in Siemens Desigo CC Client Affects Multiple Versions
CVE-2026-34223
8.6HIGH
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-34223?
A vulnerability exists in multiple versions of Siemens Desigo CC products, which is susceptible to Client Code Execution due to inadequate input validation in user-defined graphics. Attackers can embed harmful scripts within graphics documents. When a user opens one of these compromised documents, the script is run on their client device, potentially leading to arbitrary file writing on the operating system. For successful exploitation, an attacker must craft a specific malicious document and convince a user with the right privileges to open it, which can allow for broader security breaches across the organization.
Affected Version(s)
Desigo CC ClickOnce Client V6 0
Desigo CC ClickOnce Client V7 0
Desigo CC family V8 0