CVE-2026-58113
Last modified
CVE-2026-58113 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Teamcenter V2412 | < V2412.0013 |
| Siemens | Teamcenter V2506 | < V2506.0010 |
| Siemens | Teamcenter V2512 | < V2512.2607 |
| Siemens | Teamcenter V2606 | < V2606.2607 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-58113?
How severe is CVE-2026-58113?
How do I fix CVE-2026-58113?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-58101Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow de…7.5
- CVE-2026-58102Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a …9.1
- CVE-2026-58106CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-…2
- CVE-2026-58107CodeChecker's massStoreRun processing path performs one-shot…5.5
- CVE-2026-58108The personal access token removal query selects from Persona…1.2
- CVE-2026-5811A vulnerability was identified in SourceCodester Online Food…5.4
- CVE-2026-58115A vulnerability has been identified in SIMATIC IoT2050 Advan…10
- CVE-2026-58116LLaMA-Factory through 0.9.5 contains a remote code execution…8.8
- CVE-2026-5812A security flaw has been discovered in SourceCodester Pharma…5.4
- CVE-2026-58122Hermes WebUI before 0.51.307 contains an authentication bypa…9.3
- CVE-2026-58123Hermes WebUI before 0.51.788 contains an unauthenticated rem…9.8
- CVE-2026-58125Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2026-58113?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
