{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aopen-xchangeopen-xchange_appsuite_frontend7.10.6revision23/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*","cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*","cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*","cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:*:*:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:-:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision10:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision11:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision12:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision13:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision14:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision15:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision16:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision17:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision18:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision19:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision20:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision21:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision22:*:*:*:*:*:*","cpe:2.3:a:open-xchange:open-xchange_appsuite_frontend:7.10.6:revision23:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-33862"},{"cvss":8.8,"id":"CVE-2024-4367"},{"cvss":7.5,"id":"CVE-2026-33893"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=4B1110EB-8D0D-5342-B6DA-DDAA7556EEA1\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Teamcenter V2312","Teamcenter V2406","Teamcenter V2412","Teamcenter V2506","Teamcenter V2512","Firefox","Firefox Nightly"],"_cs_severities":["medium"],"_cs_tags":["cve","xss","siemens","teamcenter"],"_cs_type":"advisory","_cs_vendors":["Siemens","Mozilla"],"content_html":"\u003cp\u003eA cross-site scripting (XSS) vulnerability, identified as CVE-2026-33862, affects multiple versions of Siemens Teamcenter. Specifically, Teamcenter V2312 (all versions before V2312.0014), Teamcenter V2406 (all versions before V2406.0012), Teamcenter V2412 (all versions before V2412.0009), Teamcenter V2506 (all versions before V2506.0005), and Teamcenter V2512 are impacted. The vulnerability stems from the application's failure to properly encode or filter user-supplied data. This flaw allows a remote attacker to inject malicious scripts into the application that can then be executed by other users when they interact with the affected page, potentially leading to data theft, session hijacking, or other malicious activities. The vulnerability was reported on 2026-05-12.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts a malicious payload containing JavaScript code.\u003c/li\u003e\n\u003cli\u003eThe attacker injects the payload into a vulnerable Teamcenter input field, such as a comment, name, or description.\u003c/li\u003e\n\u003cli\u003eThe attacker submits the form or triggers the action that saves the malicious input to the Teamcenter database.\u003c/li\u003e\n\u003cli\u003eA legitimate user accesses the page or resource where the injected payload is displayed.\u003c/li\u003e\n\u003cli\u003eThe victim's web browser executes the attacker-controlled JavaScript code within the context of the Teamcenter web application.\u003c/li\u003e\n\u003cli\u003eThe malicious script can then perform actions such as stealing the user's session cookies, redirecting the user to a malicious website, or modifying the content of the page.\u003c/li\u003e\n\u003cli\u003eThe attacker can use the stolen session cookie to impersonate the user and gain unauthorized access to Teamcenter.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this XSS vulnerability (CVE-2026-33862) could lead to the execution of arbitrary JavaScript code in the context of other Teamcenter users' browsers. This can result in session hijacking, theft of sensitive information, defacement of the application, or redirection to malicious websites. Given the potential for unauthorized access and data manipulation, this vulnerability poses a significant risk to organizations using affected versions of Siemens Teamcenter.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to the latest versions of Teamcenter: V2312.0014, V2406.0012, V2412.0009, V2506.0005, or V2512 to remediate CVE-2026-33862 (see references).\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u003ccode\u003eDetect Suspicious Teamcenter URI Activity\u003c/code\u003e to identify potential exploitation attempts by monitoring for specific patterns in HTTP requests.\u003c/li\u003e\n\u003cli\u003eImplement input validation and output encoding mechanisms within the Teamcenter application to prevent XSS attacks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-27T12:00:51Z","date_published":"2026-05-12T10:20:50Z","id":"https://feed.craftedsignal.io/briefs/2026-05-cve-2026-33862/","summary":"Siemens Teamcenter versions V2312 (before V2312.0014), V2406 (before V2406.0012), V2412 (before V2412.0009), V2506 (before V2506.0005), and V2512 are vulnerable to cross-site scripting (XSS) due to improper encoding or filtering of user-supplied data, potentially leading to arbitrary code execution by other users.","title":"Siemens Teamcenter Vulnerability CVE-2026-33862 - Cross-Site Scripting","url":"https://feed.craftedsignal.io/briefs/2026-05-cve-2026-33862/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:open-Xchange:open-Xchange_appsuite_frontend:7.10.6:revision23:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}