Status: UPDATED | Advisory ID: CVE-2026-33893
| CVE | CVE-2026-33893 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-06-17 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | Siemens teamcenter, Siemens Teamcenter V2312, Siemens Teamcenter V2406, Siemens Teamcenter V2412, and Siemens Teamcenter V2506 |
| Classified as | CWE-798 (Use of Hard-coded Credentials) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Siemens | teamcenter | ||
| Siemens | Teamcenter V2312 | ||
| Siemens | Teamcenter V2406 | ||
| Siemens | Teamcenter V2412 | ||
| Siemens | Teamcenter V2506 |
| Subsystems | General OT |
| Sectors | Multiple |
A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application contains hardcoded key which is used for obfuscation stored directly into the application.
This could allow an attacker to obtain these keys and misuse them to gain unauthorized access. (NVD)
Monitor Siemens's web page for any future patch releases. See vendor advisory link below.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-33893 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-33893 |
| Vendor advisory | https://cert-portal.siemens.com/productcert/html/ssa-827383.html |