CVE-2026-34223
A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versi...
Affects 0 products across 1 vendor.
Attacker injects arbitrary code that is executed by the application process.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A high severity vulnerability (CVE-2026-34223) affects the target system. A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo...
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-34223?
What is the CVSS score for CVE-2026-34223?
Is CVE-2026-34223 actively exploited?
How do I remediate CVE-2026-34223?
What systems are affected by CVE-2026-34223?
| CVE ID | CVE-2026-34223 |
|---|---|
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
| Published | 2026-09-08 |
| Last Modified | 2026-09-22 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Source | NVD |
A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All versions), Desigo CC Installed Client V7 (All versions). The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization.
Source: NIST NVD / MITRE CVE Database
| Vendor | Product | Fixed Version |
|---|---|---|
| Siemens | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Monitoring Siemens Vulnerabilities in Your Environment?
BreachSpider tracks every Siemens CVE and maps them to your ICS assets automatically. Get email or webhook alerts when a newly published Siemens vulnerability matches your assets.
Create a free account →