Junglewise Threat Intelligence

CVE-2026-44412: Siemens Solid Edge uninitialized pointer access in PAR file parsing

CVE-2026-44412 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Siemens Solid Edge SE2026. Vendors: Siemens.

Executive brief

Siemens Solid Edge, a 3D design and manufacturing software suite, is affected by a security flaw when processing specific file types. If a user is tricked into opening a specially crafted PAR file, an attacker could potentially take control of the application or crash the system. This could lead to the theft of sensitive design data or disruption of engineering operations.

Technical details

A vulnerability exists in Siemens Solid Edge SE2026 (versions prior to V226.0 Update 5) due to the access of an uninitialized pointer (CWE-824) during the parsing of PAR files. The attack vector is local, requiring a user to open a maliciously crafted file (User Interaction required). Successful exploitation allows an attacker to execute arbitrary code in the context of the current process or cause a denial-of-service (crash). Siemens has addressed this in Solid Edge SE2026 V226.0 Update 5.

Affected products

  • Siemens Solid Edge SE2026 All versions < V226.0 Update 5

CVE identifiers

  • CVE-2026-44412
  • CVE-2026-44411

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory
  • 2026-05-13: other: Advisory updated to V1.1

References

Related threats