Status: UPDATED
| Advisory ID: CVE-2026-33862
Key Details
| CVE | CVE-2026-33862 |
| CVSS Score / Version | 7.3 (High) / CVSS v3.1 |
| Updated | 2026-06-17 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none. |
| Affected products | Siemens teamcenter, Siemens Teamcenter V2312, Siemens Teamcenter V2406, Siemens Teamcenter V2412, and Siemens Teamcenter V2506 |
| Classified as | CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application does not properly encode or filter user-supplied data. This could allow an attacker to inject malicious code that can be executed by other users when they visit the affected page. (NVD)
What to Do
Monitor Siemens's web page for any future patch releases. See vendor advisory link below.
References