Siemens Teamcenter XSS Flaw Patched
A reflected XSS bug in Siemens Teamcenter's auth redirect endpoint lets attackers hijack authenticated user sessions via crafted URLs; patches available.
Siemens has disclosed CVE-2026-58113, a reflected cross-site scripting vulnerability in the /auth/ authentication redirect flow of Teamcenter, its widely-used product lifecycle management (PLM) software. The flaw stems from improper encoding of user-supplied input reflected into HTML attribute contexts (CWE-79). An unauthenticated remote attacker can craft a malicious URL that, when loaded by an authenticated user, injects arbitrary JavaScript into that user's browser session, potentially allowing the attacker to read data or perform actions within the victim's Teamcenter session.
Affected versions span Teamcenter V2412 (prior to V2412.0013), V2506 (prior to V2506.0010), V2512 (prior to V2512.2607), and V2606 (prior to V2606.2607). Siemens has released fixed versions for all four branches and recommends organizations update immediately via the linked support portal. The vulnerability was responsibly reported by Enzo Alvarez of Bishop Fox; there is no indication of in-the-wild exploitation at this time.
This is a vendor advisory republished by CISA (ICSA-26-258-07 / Siemens SSA-157465) affecting critical manufacturing and IT sector deployments worldwide. Defenders should prioritize patching, minimize network exposure of Teamcenter instances, avoid direct internet accessibility, and apply standard XSS mitigations such as monitoring for anomalous authentication-flow URL parameters and educating users against clicking untrusted links to Teamcenter authentication endpoints.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-07
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free