Cross-Site Scripting Vulnerability in Element Maps-ng by Siemens
CVE-2026-66155
7HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 27 August 2026
What is CVE-2026-66155?
A vulnerability exists in Siemens' Element maps-ng that allows improper handling of user-controllable input in the si-map component. This flaw affects specific versions of the product and could enable attackers to craft a malicious URL. When this URL is accessed and a particular map pin is hovered over by a victim, the vulnerable component can execute arbitrary script code within the victim's browser, potentially compromising user data and security.
Affected Version(s)
Element maps-ng V47 0
Element maps-ng V48 0
Element maps-ng V49 0