Web Application Vulnerability in Teamcenter by Siemens
CVE-2026-58113

8.5HIGH

Key Information:

Vendor

Siemens

Vendor
CVE Published:
8 September 2026

What is CVE-2026-58113?

A vulnerability in Siemens Teamcenter applications allows unauthenticated remote attackers to exploit improperly encoded user-supplied input in the authentication redirect flow. Specifically, this weakness exists within the /auth/ endpoint, where malicious JavaScript can be injected into browsers of authenticated users who access specially crafted URLs. This could permit attackers to carry out unauthorized actions within the impacted Teamcenter sessions, posing significant security risks to users.

Affected Version(s)

Teamcenter V2412 0

Teamcenter V2506 0

Teamcenter V2512 0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.