| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2026-58113 | 6.1 | medium |
CVE-2026-58113. Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint).
This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.
|