CVE-2026-58113

MEDIUM

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (Al...

Affects 0 products across 1 vendor.

CVSS 3.16.1
CVSS v48.5
EPSS0.4%
Percentile29th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, requires user interaction, can impact systems beyond the vulnerable component, no availability impact.
CWE Weakness Definitions
CWE-79: Cross-Site Scripting (XSS)

Attacker injects malicious scripts into web pages viewed by other users, executing in the victim's browser context.

Related Attack Patterns (CAPEC)
CAPEC-85 AJAX Footprinting
via CWE-79
CAPEC-209 XSS Using MIME Type Mismatch
via CWE-79
CAPEC-588 DOM-Based XSS
via CWE-79
CAPEC-591 Reflected XSS
via CWE-79
CAPEC-592 Stored XSS
via CWE-79
Show all 6
via CWE-79

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A medium severity vulnerability (CVE-2026-58113) affects the target system. A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do no...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-58113?
A medium severity vulnerability (CVE-2026-58113) affects the target system. A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do no...
What is the CVSS score for CVE-2026-58113?
CVE-2026-58113 has CVSS 6.1 (Medium). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. EPSS: 0.4%.
Is CVE-2026-58113 actively exploited?
No confirmed active exploitation of CVE-2026-58113 as of 2026-09-25.
How do I remediate CVE-2026-58113?
Apply vendor patches for CVE-2026-58113. Monitor Siemens advisories.
What systems are affected by CVE-2026-58113?
CVE-2026-58113 affects: Siemens.
Vulnerability Details
CVE IDCVE-2026-58113
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Published2026-09-08
Last Modified2026-09-15
ICS Relevance55%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Siemens &mdash; —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 20 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Siemens
CVE-2007-1917 10.0 Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library... CVE-2026-56451 10.0 A vulnerability has been identified in Opcenter X (All versions < V2604). Aff... CVE-2008-6916 10.0 Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to... CVE-2008-6993 10.0 Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allo... CVE-2011-4514 10.0 The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC...
View all Siemens CVEs →

Monitoring Siemens Vulnerabilities in Your Environment?

BreachSpider tracks every Siemens CVE and maps them to your ICS assets automatically. Get email or webhook alerts when a newly published Siemens vulnerability matches your assets.

Create a free account →