<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Teamcenter (V2412 &lt; 2412.0013) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/teamcenter-v2412--2412.0013/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 16:31:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/teamcenter-v2412--2412.0013/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Reflected Cross-Site Scripting Vulnerability in Siemens Teamcenter</title><link>https://feed.craftedsignal.io/briefs/2026-09-siemens-teamcenter-xss/</link><pubDate>Tue, 15 Sep 2026 16:31:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-siemens-teamcenter-xss/</guid><description>An unauthenticated remote attacker can exploit a reflected XSS vulnerability in the Teamcenter authentication redirect flow to execute arbitrary JavaScript in the context of an authenticated user session.</description><content:encoded><![CDATA[<p>Siemens Teamcenter versions V2412, V2506, V2512, and V2606 are vulnerable to a reflected cross-site scripting (XSS) vulnerability (CVE-2026-58113) located in the authentication redirect flow. The vulnerability arises due to improper neutralization of user-supplied input when reflected into HTML attribute contexts within the /auth/ endpoint. An unauthenticated attacker can craft a malicious URL containing payload-injected parameters to target an authenticated user. When the victim loads this URL, the injected script executes within the victim's active session, potentially allowing the attacker to perform actions on the user's behalf or access sensitive data. Siemens has released patched versions for the affected product families and advises users to upgrade immediately to remediate the flaw.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript within the context of an authenticated user's session. This could lead to session hijacking, unauthorized data exfiltration, or the performance of unauthorized actions within the Teamcenter application. The vulnerability affects critical manufacturing and information technology sectors globally.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching affected Teamcenter installations to the versions specified by the vendor:</p>
<ul>
<li>Update Teamcenter V2412 to V2412.0013 or later.</li>
<li>Update Teamcenter V2506 to V2506.0010 or later.</li>
<li>Update Teamcenter V2512 to V2512.2607 or later.</li>
<li>Update Teamcenter V2606 to V2606.2607 or later.</li>
<li>Apply defense-in-depth strategies to isolate Teamcenter instances from the public internet, as recommended by the vendor.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>web-vulnerability</category><category>xss</category><category>siemens</category></item></channel></rss>