Description
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Published: 2026-08-11
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds read (CWE-125) in Solid Edge’s DFT file parser. When a specially crafted DFT file is parsed, the application may read memory beyond the intended bounds, allowing an attacker to influence code execution in the same security context as the running process. This results in loss of confidentiality, integrity and availability of the affected system.

Affected Systems

Siemens Solid Edge SE2025 versions earlier than V225.0 Update 15 and Siemens Solid Edge SE2026 versions earlier than V226.0 Update 7 are affected. Any system running these older releases is vulnerable when a malicious DFT file is opened or imported.

Risk and Exploitability

The CVSS score of 7.3 classifies this vulnerability as high severity. No EPSS data is available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation at the time of assessment. The likely attack vector involves an attacker delivering a specially crafted DFT file, which a user may open locally or via a file share; this inference is drawn from the description that the flaw occurs while parsing DFT files.

Generated by OpenCVE AI on August 11, 2026 at 23:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Solid Edge update: update SE2025 to Update 15 or later, and SE2026 to Update 7 or later, which contain the fix for the parsing bug.
  • Restrict or monitor access to DFT files by limiting user permissions or disabling the import feature in application settings where appropriate.
  • Implement monitoring for anomalous memory read activity or unexpected code execution patterns to detect exploitation attempts early.

Generated by OpenCVE AI on August 11, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Solid Edge DFT Parser Out-of-Bounds Read Enables Local Code Execution
First Time appeared Siemens
Siemens solid Edge Se2025
Siemens solid Edge Se2026
Vendors & Products Siemens
Siemens solid Edge Se2025
Siemens solid Edge Se2026

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Solid Edge Se2025 Solid Edge Se2026
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-11T14:52:35.327Z

Reserved: 2026-06-03T11:07:02.667Z

Link: CVE-2026-50058

cve-icon Vulnrichment

Updated: 2026-08-11T14:52:31.602Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T13:18:58.153

Modified: 2026-08-28T19:03:37.837

Link: CVE-2026-50058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T00:00:03Z

Weaknesses