Junglewise Threat Intelligence

CVE-2026-58113: Siemens Teamcenter reflected cross-site scripting in authentication redirect

CVE-2026-58113 · Severity: medium · CVSS 6.1 · Published 2026-09-08

Technologies: Siemens Teamcenter. Vendors: Siemens.

Executive brief

Siemens Teamcenter is a product lifecycle management (PLM) system used to manage product design, engineering, and manufacturing processes across organizations. A reflected cross-site scripting vulnerability in the authentication redirect flow allows an unauthenticated attacker to craft a malicious URL that, when clicked by an authenticated user, injects arbitrary JavaScript code into the user's browser session. An attacker exploiting this could read sensitive data or perform unauthorized actions within the victim's Teamcenter account.

Technical details

This is a reflected cross-site scripting (XSS) vulnerability (CWE-79) in Siemens Teamcenter's authentication redirect flow (/auth/ endpoint). The vulnerability exists because user-supplied input is not properly encoded before being reflected into HTML attribute contexts. The attack requires user interaction (the victim must click a crafted link) but no authentication on the attacker's side. An unauthenticated attacker can inject arbitrary JavaScript that executes in the context of an authenticated user's session, allowing them to read session data, perform actions as the victim, or steal credentials. Siemens has released patched versions for all affected product lines (V2412.0013, V2506.0010, V2512.2607, V2606.2607 and later).

Affected products

  • Siemens Teamcenter V2412 < V2412.0013, V2506 < V2506.0010, V2512 < V2512.2607, V2606 < V2606.2607

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory: Siemens SSA-157465 published

References

Related threats