CVE-2026-66155: Siemens Element Maps-NG v47

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session.

Affected products

  • Siemens Element Maps-NG v47: before V47.12.3 (fixed in V47.12.3)
  • Siemens Element Maps-NG v48: before V48.11.3 (fixed in V48.11.3)
  • Siemens Element Maps-NG v49: before V49.16.1 (fixed in V49.16.1)

Published 2026-08-27. Last modified 2026-08-28.