Answer in brief
CVE-2026-58113 records a Unknown severity vulnerability in CISA ADP Vulnrichment. The current sources do not mark it as known exploited. The current feed maps Siemens/Teamcenter V2412 (generic), Siemens/Teamcenter V2506 (generic), Siemens/Teamcenter V2512 (generic), Siemens/Teamcenter V2606 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Siemens/Teamcenter V2412 (generic), Siemens/Teamcenter V2506 (generic), Siemens/Teamcenter V2512 (generic), Siemens/Teamcenter V2606 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Siemens/Teamcenter V2412generic | >=0 <V2412.0013 | V2412.0013 |
| Siemens/Teamcenter V2506generic | >=0 <V2506.0010 | V2506.0010 |
| Siemens/Teamcenter V2512generic | >=0 <V2512.2607 | V2512.2607 |
| Siemens/Teamcenter V2606generic | >=0 <V2606.2607 | V2606.2607 |
Published upstream
Sep 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 8, 2026
A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.
Quoted source text, attributed separately from HOL analysis.