Executive brief
Solid Edge is a professional 3D design and manufacturing software suite used by engineers and product development teams. The application fails to properly validate memory boundaries when processing specially crafted DFT design files, allowing an attacker to crash the application or execute arbitrary code with the privileges of the user running Solid Edge. An attacker could embed malicious DFT files in design projects or email attachments to compromise a designer's workstation.
Technical details
CVE-2026-50058 is an out-of-bounds read vulnerability (CWE-125) triggered during DFT file parsing in Solid Edge SE2025 and SE2026. The vulnerability requires user interaction—an attacker must trick a user into opening a specially crafted DFT file—and operates with local attack vector since the file must be processed by the client application. Successful exploitation allows arbitrary code execution in the context of the Solid Edge process. Patches are available: SE2025 requires update to V225.0 Update 15 or later, and SE2026 requires update to V226.0 Update 7 or later.
Affected products
- Siemens Solid Edge SE2025 All versions < V225.0 Update 15
- Siemens Solid Edge SE2026 All versions < V226.0 Update 7
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: SE2025 update to V225.0 Update 15; SE2026 update to V226.0 Update 7