CVE-2026-58113: Siemens Teamcenter v2412
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.
Affected products
- Siemens Teamcenter v2412: before V2412.0013 (fixed in V2412.0013)
- Siemens Teamcenter v2506: before V2506.0010 (fixed in V2506.0010)
- Siemens Teamcenter v2512: before V2512.2607 (fixed in V2512.2607)
- Siemens Teamcenter v2606: before V2606.2607 (fixed in V2606.2607)
Published 2026-09-08. Last modified 2026-09-09.