Junglewise Threat Intelligence

CVE-2026-50063: Siemens Solid Edge out-of-bounds read in PAR file parsing

CVE-2026-50063 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Siemens Solid Edge Se2025. Vendors: Siemens.

Executive brief

Solid Edge is a professional 3D CAD design and manufacturing software suite used by engineering teams to develop products. A flaw in how the application processes specially crafted PAR design files could allow an attacker to execute arbitrary code with the privileges of the logged-in user, potentially compromising intellectual property, design data, and system access.

Technical details

CVE-2026-50063 is an out-of-bounds read vulnerability (CWE-125) in Solid Edge's PAR file parser. The vulnerability is triggered when the application reads a specially crafted PAR file without proper bounds checking, allowing an attacker to read memory beyond intended buffer limits. The attack requires user interaction—the attacker must trick or socially engineer a user into opening a malicious PAR file—and the vulnerability resides in the file parsing logic. Successful exploitation can result in arbitrary code execution in the context of the current process. Patches are available: SE2025 users should update to V225.0 Update 15 or later; SE2026 users should update to V226.0 Update 7 or later.

Affected products

  • Siemens Solid Edge SE2025 All versions < V225.0 Update 15
  • Siemens Solid Edge SE2026 All versions < V226.0 Update 7

Timeline

  • 2026-08-11: disclosed: CVE-2026-50063 published by Siemens ProductCERT
  • 2026-08-11: patched: Patches released: SE2025 V225.0 Update 15 and SE2026 V226.0 Update 7

References

Related threats