Status: UPDATED | Advisory ID: CVE-2026-66155
| CVE | CVE-2026-66155 |
| CVSS Score / Version | 7.6 (High) / CVSS v3.1 |
| Updated | 2026-08-28 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is required; scope is changed; confidentiality impact is high; integrity impact is low; availability impact is none. |
| Affected products | Siemens Element maps-ng V47, Siemens Element maps-ng V48, and Siemens Element maps-ng V49 |
| Classified as | CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Siemens | Element maps-ng V47 | ||
| Siemens | Element maps-ng V48 | ||
| Siemens | Element maps-ng V49 |
| Subsystems | General OT |
| Sectors | Multiple |
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins.
This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session. (NVD)
Monitor Siemens's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-66155 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-66155 |