Executive Summary

CVE-2026-58113 is a reflected cross-site scripting flaw in the Teamcenter authentication redirect flow at the /auth/ endpoint, where user-supplied input is reflected into HTML attribute contexts without proper encoding. An unauthenticated remote attacker who convinces an authenticated engineer to load a crafted URL can execute arbitrary JavaScript in that user's browser session and perform actions inside the victim's Teamcenter instance.

Technical Exposure Breakdown

The defect lives in the encoding boundary of the authentication redirect path. Affected applications reflect attacker-controlled input into an HTML attribute context during the redirect flow and fail to encode it. When the browser parses the response, the injected payload breaks out of the intended attribute and executes as script in the origin of the Teamcenter web application.

The affected versions per the grounding data are Teamcenter V2412 (all versions below V2412.0013), V2506 (all versions below V2506.0010), V2512 (all versions below V2512.2607), and V2606 (all versions below V2606.2607). The CVSS score is 6.1.

The attack is unauthenticated at the injection point but requires a target that already holds a valid Teamcenter session. This is a classic reflected XSS delivery model. There is no memory corruption and no need for the attacker to hold credentials. The attacker crafts the URL, delivers it through email, chat, or a shared link, and waits for an authenticated user to click. Because the payload executes in the context of the victim, it inherits the victim's session tokens, roles, and access to product lifecycle data.

The physical severity here is not a process disruption. It is a data integrity and access risk against the engineering system of record. Teamcenter is the product lifecycle management backbone in many manufacturing and industrial organizations. It holds CAD assemblies, bills of material, change orders, controlled documents, and manufacturing definitions. Session-riding actions against a privileged Teamcenter user can alter change records, exfiltrate proprietary designs, or manipulate the data that feeds downstream manufacturing execution systems.

OT Impact and Compliance Risk

Teamcenter usually sits in the enterprise or engineering zone rather than on a Level 1 or Level 2 control network, so this is not a vulnerability that will brick a PLC. The line between IT assumptions and OT reality still matters. PLM systems are the authoritative source for the design and manufacturing definitions that eventually become firmware, machine configurations, and controlled product data. Compromising the integrity of that source is a supply chain integrity problem, not just a web application bug.

Under IEC 62443, this maps to zone and conduit integrity concerns and to the SR requirements around input validation and session protection. For organizations that treat their engineering environment as an IEC 62443 zone, a reflected XSS that permits session-context actions undermines the assumed trust boundary between an authenticated engineer and the PLM origin. Where Teamcenter data flows into NERC CIP regulated environments as part of BES cyber system configuration or documentation, the integrity of that data path becomes relevant to CIP-010 configuration change management and CIP-011 information protection controls.

Compensating Controls

Do not rely on patch timing alone. The patch status in the grounding data is unknown, and even when a fix is available, engineering environments often defer PLM upgrades because of validation cycles.

BreachSpider Intel

BreachSpider tracks exploitation signals and version exposure for CVE-2026-58113 across PLM and engineering environments so operators can prioritize based on real reachability rather than CVSS alone.