Executive brief
Siemens Teamcenter, a product lifecycle management (PLM) system used to manage industrial design and manufacturing data, is vulnerable to a security flaw where it fails to properly clean user-provided information. An attacker with basic user access could inject malicious scripts into the system that execute when other users view specific pages. This could lead to the theft of sensitive session information or unauthorized actions being performed on behalf of legitimate users, potentially compromising intellectual property or operational data.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in multiple versions of Siemens Teamcenter (CWE-79). The root cause is the application's failure to properly encode or filter user-supplied data before it is rendered in web pages. An attacker with low-privileged network access can inject malicious scripts into the application. When other users navigate to the affected page, the script executes in their browser context. This can be used to steal session tokens, perform actions on behalf of the victim, or exfiltrate sensitive PLM data. Siemens has released patches for versions V2312, V2406, V2412, and V2506 to address this issue.
Affected products
- Siemens Teamcenter V2312 < V2312.0014, V2406 < V2406.0012, V2412 < V2412.0009, V2506 < V2506.0005
CVE identifiers
- CVE-2026-33862
- CVE-2026-33893
- CVE-2024-4367
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
- 2026-05-12: patched