← All Advisories

CVE-2026-66155

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-66155

Key Details

CVECVE-2026-66155
CVSS Score / Version7.6 (High) / CVSS v3.1
Updated2026-08-28
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is required; scope is changed; confidentiality impact is high; integrity impact is low; availability impact is none.
Affected productsSiemens Element maps-ng V47, Siemens Element maps-ng V48, and Siemens Element maps-ng V49
Classified asCWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensElement maps-ng V47
SiemensElement maps-ng V48
SiemensElement maps-ng V49
SubsystemsGeneral OT
SectorsMultiple

What to Know

A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins.

This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-66155
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-66155