CVE-2026-34223
Last modified
CVE-2026-34223 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All versions), Desigo CC Installed Client V7 (All versions). The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All versions), Desigo CC Installed Client V7 (All versions). The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Desigo CC ClickOnce Client V6 | < * |
| Siemens | Desigo CC ClickOnce Client V7 | < * |
| Siemens | Desigo CC family V8 | All versions |
| Siemens | Desigo CC family V9 | All versions |
| Siemens | Desigo CC Flex Client V6 | All versions |
| Siemens | Desigo CC Flex Client V7 | All versions |
| Siemens | Desigo CC Installed Client V6 | < * |
| Siemens | Desigo CC Installed Client V7 | < * |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-34223?
How severe is CVE-2026-34223?
How do I fix CVE-2026-34223?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34218ClearanceKit intercepts file-system access events on macOS a…6.3
- CVE-2026-34219libp2p-rust is the official rust language Implementation of …5.9
- CVE-2026-3422U-Office Force developed by e-Excellence has a Insecure Dese…9.8
- CVE-2026-34220MikroORM is a TypeScript ORM for Node.js based on Data Mappe…9.8
- CVE-2026-34221MikroORM is a TypeScript ORM for Node.js based on Data Mappe…9.1
- CVE-2026-34222Open WebUI is a self-hosted artificial intelligence platform…7.7
- CVE-2026-34224Parse Server is an open source backend that can be deployed …4.4
- CVE-2026-34225Open WebUI is a self-hosted artificial intelligence platform…4.3
- CVE-2026-34226Happy DOM is a JavaScript implementation of a web browser wi…7.5
- CVE-2026-34227Sliver is a command and control framework that uses a custom…8.8
- CVE-2026-34228Emlog is an open source website building system. Prior to ve…6.5
- CVE-2026-34229Emlog is an open source website building system. Prior to ve…6.1
Are you affected by CVE-2026-34223?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
