PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-33862 Siemens CVE debrief

CVE-2026-33862 is a high-severity cross-site scripting issue in Siemens Teamcenter. The advisory says the affected application does not properly encode or filter user-supplied data, which can let an attacker inject malicious code that executes when other users visit the affected page. CISA published the advisory on 2026-05-12 and republished Siemens ProductCERT guidance on 2026-05-14.

Vendor
Siemens
Product
Teamcenter V2312
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Organizations running affected Siemens Teamcenter deployments, especially PLM administrators, application owners, and security teams responsible for browser-facing workflows and user-supplied content handling.

Technical summary

The flaw is consistent with reflected or stored XSS (CWE-79): user-controlled input is not properly encoded or filtered before being rendered to other users. The provided CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N, indicating network reachability, low attack complexity, limited privileges required, and user interaction required, with high confidentiality and integrity impact.

Defensive priority

High

Recommended defensive actions

  • Update affected Siemens Teamcenter installations to the fixed releases listed by the vendor: V2312.0014 or later, V2406.0012 or later, V2412.0009 or later, and V2506.0005 or later.
  • Inventory Teamcenter instances and confirm which releases are in use before planning remediation.
  • Review pages and workflows that render user-supplied input, especially where content is visible to other users.
  • Validate that the patched version is deployed successfully and that the vendor guidance for the advisory has been applied.
  • Monitor for anomalous script injection attempts or unexpected browser-side behavior in Teamcenter-related pages.
  • Prioritize remediation for deployments exposed to many users or to broader internal network access.

Evidence notes

This debrief is based on the CISA CSAF advisory ICSA-26-134-04, which CISA notes is a republication of Siemens ProductCERT advisory SSA-827383. The supplied advisory text explicitly describes improper encoding/filtering of user-supplied data leading to malicious code execution in other users’ browsers. No KEV entry is present in the provided data.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-33862 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-33862

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-33862 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-33862

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-827383.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-827383.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.