{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/teamcenter-v2506--2506.0010/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.1,"id":"CVE-2026-58113"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Teamcenter (V2412 \u003c 2412.0013)","Teamcenter (V2506 \u003c 2506.0010)","Teamcenter (V2512 \u003c 2512.2607)","Teamcenter (V2606 \u003c 2606.2607)"],"_cs_severities":["low"],"_cs_tags":["web-vulnerability","xss","siemens"],"_cs_type":"advisory","_cs_vendors":["Siemens"],"content_html":"\u003cp\u003eSiemens Teamcenter versions V2412, V2506, V2512, and V2606 are vulnerable to a reflected cross-site scripting (XSS) vulnerability (CVE-2026-58113) located in the authentication redirect flow. The vulnerability arises due to improper neutralization of user-supplied input when reflected into HTML attribute contexts within the /auth/ endpoint. An unauthenticated attacker can craft a malicious URL containing payload-injected parameters to target an authenticated user. When the victim loads this URL, the injected script executes within the victim's active session, potentially allowing the attacker to perform actions on the user's behalf or access sensitive data. Siemens has released patched versions for the affected product families and advises users to upgrade immediately to remediate the flaw.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript within the context of an authenticated user's session. This could lead to session hijacking, unauthorized data exfiltration, or the performance of unauthorized actions within the Teamcenter application. The vulnerability affects critical manufacturing and information technology sectors globally.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching affected Teamcenter installations to the versions specified by the vendor:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Teamcenter V2412 to V2412.0013 or later.\u003c/li\u003e\n\u003cli\u003eUpdate Teamcenter V2506 to V2506.0010 or later.\u003c/li\u003e\n\u003cli\u003eUpdate Teamcenter V2512 to V2512.2607 or later.\u003c/li\u003e\n\u003cli\u003eUpdate Teamcenter V2606 to V2606.2607 or later.\u003c/li\u003e\n\u003cli\u003eApply defense-in-depth strategies to isolate Teamcenter instances from the public internet, as recommended by the vendor.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T16:31:40Z","date_published":"2026-09-15T16:31:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-siemens-teamcenter-xss/","summary":"An unauthenticated remote attacker can exploit a reflected XSS vulnerability in the Teamcenter authentication redirect flow to execute arbitrary JavaScript in the context of an authenticated user session.","title":"Reflected Cross-Site Scripting Vulnerability in Siemens Teamcenter","url":"https://feed.craftedsignal.io/briefs/2026-09-siemens-teamcenter-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Teamcenter (V2506 \u003c 2506.0010)","version":"https://jsonfeed.org/version/1.1"}