CVE-2026-58113
Deferred Deferred - Pending Action

Cross-Site Scripting in Siemens Teamcenter

Vulnerability report for CVE-2026-58113, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: siemens-SADP

Description

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
siemens teamcenter to 2412.0013 (exc)
siemens teamcenter to 2506.0010 (exc)
siemens teamcenter to 2512.2607 (exc)
siemens teamcenter to 2606.2607 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a reflected cross-site scripting (XSS) vulnerability in Siemens Teamcenter software. It occurs in the authentication redirect flow (/auth/ endpoint) where user-supplied input is not properly encoded when reflected into HTML attribute contexts. An unauthenticated remote attacker can inject malicious JavaScript into an authenticated user's session by tricking them into clicking a specially crafted URL.

Detection Guidance

Detecting this vulnerability requires checking if your Teamcenter versions are outdated. Verify installed versions against patched releases (V2412.0013 or later, V2506.0010 or later, V2512.2607 or later, V2606.2607 or later). Inspect network traffic for suspicious URLs targeting the /auth/ endpoint.

Impact Analysis

If exploited, this vulnerability could allow an attacker to read sensitive data or perform unauthorized actions within the victim's Teamcenter session. This includes accessing or modifying data, performing administrative actions, or taking control of the user's session without their knowledge.

Mitigation Strategies

Immediately update Teamcenter to the latest patched versions (V2412.0013 or later, V2506.0010 or later, V2512.2607 or later, V2606.2607 or later). Restrict network access to the /auth/ endpoint and follow Siemens' Industrial Security guidelines.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58113. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart