CVE-2026-22923

HIGH

Siemens NX < 2512.0 - Stack-based Buffer Overflow in PDF Export

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in NX (All versions < V2512), NX (Managed Mode) (All versions < V2512). The affected application contains a data validation vulnerability that could allow an attacker with local access to interfere with internal data during the PDF export process that could potentially lead to arbitrary code execution.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 0.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Products (1)
siemens/nx < 2512.0
Published Feb 10, 2026
Tracked Since Feb 18, 2026