CVE-2026-33862

A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application does not properly encode or filter user-supplied data. This could allow an attacker to inject malicious code that can be executed by other users when they visit the affected page.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*

History

18 May 2026, 17:23

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*
First Time Siemens
Siemens teamcenter
References () https://cert-portal.siemens.com/productcert/html/ssa-827383.html - () https://cert-portal.siemens.com/productcert/html/ssa-827383.html - Vendor Advisory

12 May 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 10:16

Updated : 2026-05-18 17:23


NVD link : CVE-2026-33862

Mitre link : CVE-2026-33862

CVE.ORG link : CVE-2026-33862


JSON object : View

Products Affected

siemens

  • teamcenter
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')