VORANT. Threat Intelligence Sign in Get the full feed

Siemens Industrial Edge Management auth bypass flaw

elevated vulnerability manufacturing

An unauthenticated attacker can bypass email verification to reset credentials and take over accounts in Siemens Industrial Edge Management.

Siemens Industrial Edge Management is affected by an authentication bypass vulnerability (CVE-2026-18963) in the reset-credentials flow of the keycloak-services component, which underpins identity and access management in Red Hat Build of Keycloak. The flaw allows an unauthenticated remote attacker to force a password reset for any user account without needing to complete the required email verification step, resulting in full account takeover by directly setting new credentials.

Affected products include Industrial Edge Management Cloud (all versions), Industrial Edge Management Pro V1 (>=1.14.9, <1.15.20), Pro V2 (>=2.2.0, <2.2.2), and Virtual (>=2.6.0, <2.9.1). Siemens has released fixed versions (V1.15.20, V2.2.2, V2.9.1) and applied firewall-based mitigations on 2026-08-26, with the vendor fix completed 2026-09-02. Interim mitigations include blocking direct internet access to IEM Pro/Virtual instances, blocking the /auth/realms/customer/login-actions/reset-credentials path via WAF/reverse proxy, or disabling password reset functionality in Keycloak realm settings.

This is a critical manufacturing sector ICS advisory from CISA, republished verbatim from Siemens ProductCERT SSA-503852. No evidence of in-the-wild exploitation is mentioned in the advisory. Defenders operating affected Industrial Edge Management deployments should prioritize patching or applying the documented mitigations, and should ensure control system components are not directly exposed to the internet as a general practice.

Mentioned in this report

Vulnerabilities CVE-2026-18963templated

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-06

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free