Reflected Cross-site scripting Vulnerability in Teamcenter

MonitorCVSS 6.1SSA-157465Sep 8, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

A reflected cross-site scripting vulnerability exists in the authentication redirect flow (/auth/) of Siemens Teamcenter. An unauthenticated attacker can craft a malicious URL containing injected JavaScript that executes within an authenticated user's session. Successful exploitation allows the attacker to read sensitive data or perform actions on behalf of the victim within Teamcenter, such as accessing design files, stealing intellectual property, or modifying product data. The vulnerability affects Teamcenter V2412 (before 2412.0013), V2506 (before 2506.0010), V2512 (before 2512.2607), and V2606 (before 2606.2607).

What this means
What could happen
An attacker could trick a Teamcenter user into clicking a malicious link that runs JavaScript code within their authenticated session, potentially allowing the attacker to steal data, modify design files, or impersonate the user within the platform.
Who's at risk
This affects organizations using Siemens Teamcenter for product lifecycle management (PLM), including design engineering departments, manufacturing planning teams, and any staff who manage or access product data through Teamcenter. The vulnerability impacts all currently supported versions across 2412, 2506, 2512, and 2606 release lines.
How it could be exploited
An attacker crafts a malicious URL containing injected JavaScript in the authentication redirect flow (/auth/) and sends it to a Teamcenter user (typically via email or messaging). When the authenticated user clicks the link, the JavaScript executes in their browser session, giving the attacker access to their session context and capabilities.
Prerequisites
  • User must be logged into Teamcenter
  • User must click a malicious link provided by the attacker
  • No special network access required; exploitation occurs via URL injection in the browser
remotely exploitablelow complexityrequires user interaction (link click)reflected XSS allows session hijacking and data theft
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (4)
4 with fix
ProductAffected VersionsFix Status
Teamcenter V2412 < V2412.0013< 2412.00132412.0013
Teamcenter V2506 < V2506.0010< 2506.00102506.0010
Teamcenter V2512 < V2512.2607< 2512.26072512.2607
Teamcenter V2606 < V2606.2607< 2606.26072606.2607
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Teamcenter V2412 to version 2412.0013 or later
HOTFIXUpdate Teamcenter V2506 to version 2506.0010 or later
HOTFIXUpdate Teamcenter V2512 to version 2512.2607 or later
HOTFIXUpdate Teamcenter V2606 to version 2606.2607 or later
API: /api/v1/advisories/f2d31a90-c4df-4de2-be2c-6b19a857909f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Reflected Cross-site scripting Vulnerability in Teamcenter | CVSS 6.1 - OTPulse