CVE-2026-33862
HIGHSiemens Teamcenter V2312 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Title source: ruleDescription
A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application does not properly encode or filter user-supplied data. This could allow an attacker to inject malicious code that can be executed by other users when they visit the affected page.
References (1)
Core 1
Core References
Scores
CVSS v3
7.3
EPSS
0.0003
EPSS Percentile
9.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (6)
siemens/teamcenter
2312.0 - 2312.0014
Siemens/Teamcenter V2312
< V2312.0014
Siemens/Teamcenter V2406
< V2406.0012
Siemens/Teamcenter V2412
< V2412.0009
Siemens/Teamcenter V2506
< V2506.0005
Siemens/Teamcenter V2512
Published
May 12, 2026
Tracked Since
May 12, 2026