Executive brief
Solid Edge is a professional 3D CAD design and manufacturing software suite used by engineering teams to develop products. A flaw in how the application processes specially crafted PAR design files could allow an attacker to execute arbitrary code with the privileges of the logged-in user, potentially compromising intellectual property, design data, and system access.
Technical details
CVE-2026-50063 is an out-of-bounds read vulnerability (CWE-125) in Solid Edge's PAR file parser. The vulnerability is triggered when the application reads a specially crafted PAR file without proper bounds checking, allowing an attacker to read memory beyond intended buffer limits. The attack requires user interaction—the attacker must trick or socially engineer a user into opening a malicious PAR file—and the vulnerability resides in the file parsing logic. Successful exploitation can result in arbitrary code execution in the context of the current process. Patches are available: SE2025 users should update to V225.0 Update 15 or later; SE2026 users should update to V226.0 Update 7 or later.
Affected products
- Siemens Solid Edge SE2025 All versions < V225.0 Update 15
- Siemens Solid Edge SE2026 All versions < V226.0 Update 7
Timeline
- 2026-08-11: disclosed: CVE-2026-50063 published by Siemens ProductCERT
- 2026-08-11: patched: Patches released: SE2025 V225.0 Update 15 and SE2026 V226.0 Update 7