Junglewise Threat Intelligence

CVE-2026-50062: Siemens Solid Edge out-of-bounds read in PAR file parsing

CVE-2026-50062 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Siemens Solid Edge Se2025. Vendors: Siemens.

Executive brief

Siemens Solid Edge is a professional 3D design and product development software suite used by manufacturing and engineering organizations. A vulnerability in file parsing allows attackers to execute arbitrary code by crafting malicious PAR design files. An attacker can trick users into opening a malicious file, leading to compromise of the user's system and potentially the design intellectual property stored within.

Technical details

CVE-2026-50062 is an out-of-bounds read vulnerability (CWE-125) in Solid Edge's PAR file parser. The vulnerability occurs when the application processes specially crafted PAR files without proper bounds checking. The attack vector is local with user interaction required—an attacker must craft a malicious PAR file and convince a user to open it within Solid Edge. Successful exploitation allows arbitrary code execution in the context of the Solid Edge process. Patches are available: Solid Edge SE2025 requires V225.0 Update 15 or later, and SE2026 requires V226.0 Update 7 or later.

Affected products

  • Siemens Solid Edge SE2025 All versions < V225.0 Update 15
  • Siemens Solid Edge SE2026 All versions < V226.0 Update 7

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Updates available: SE2025 V225.0 Update 15, SE2026 V226.0 Update 7

References

Related threats