SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-58113

MEDIUM · CVSS 6.1 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Teamcenter versions prior to V2412.0013, V2506.0010, V2512.2607, and V2606.2607 are vulnerable due to improper encoding of user-supplied input in the authentication redirect flow, specifically at the /auth/ endpoint. This flaw allows unauthenticated remote attackers to inject arbitrary JavaScript into the browsers of authenticated users, potentially compromising their Teamcenter sessions. Organizations using affected versions should prioritize patching to mitigate the risk of session hijacking and unauthorized actions.

CVE
CVE-2026-58113
Severity
MEDIUM
CVSS
6.1
EPSS
0.22%
Java

Original NVD Description

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.