IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-157465: Reflected Cross-site scripting Vulnerability in Teamcenter

MEDIUM
CVSS 6.1
Date 2026-09-08T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-58113 6.1 medium
CVE-2026-58113. Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.

// Remediations (4)

Patch: Update to V2606.2607 or later version
Update to V2606.2607 or later version
Patch: Update to V2512.2607 or later version
Update to V2512.2607 or later version
Patch: Update to V2412.0013 or later version
Update to V2412.0013 or later version
Patch: Update to V2506.0010 or later version
Update to V2506.0010 or later version

// References