Description
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Published: 2026-08-11
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An application use‑after‑free flaw in Siemens Solid Edge SE2025 and SE2026 can be triggered by parsing a specially crafted DFT file, allowing an attacker to run arbitrary code within the user’s process context. The weakness falls under CWE‑416 and can compromise confidentiality, integrity, and availability of the affected system.

Affected Systems

The vulnerability affects Siemens Solid Edge SE2025 versions earlier than V225.0 Update 15 and Siemens Solid Edge SE2026 versions earlier than V226.0 Update 7. Users running these product releases are at risk when handling untrusted DFT files.

Risk and Exploitability

The CVSS score is 7.3, indicating a high severity risk. EPSS is not available and the vulnerability is not listed in CISA KEV. The likely attack vector is local or remote supply‑chain delivery of a malicious DFT file; after the use‑after‑free can be exploited to attain code execution.

Generated by OpenCVE AI on August 11, 2026 at 23:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest update for Solid Edge SE2025 (V225.0 Update 15 or later) or Solid Edge SE2026 (V226.0 Update 7 or later).
  • Restrict write and execution permissions for DFT files to trusted users and environments.
  • Use file‑integrity or antivirus scanning to detect malicious DFT files before opening them.

Generated by OpenCVE AI on August 11, 2026 at 23:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens solid Edge Se2025
Siemens solid Edge Se2026
Vendors & Products Siemens
Siemens solid Edge Se2025
Siemens solid Edge Se2026

Wed, 12 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Solid Edge SE2025/SE2026 Enables Code Execution

Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Solid Edge Se2025 Solid Edge Se2026
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-11T12:20:16.329Z

Reserved: 2026-06-03T11:07:02.668Z

Link: CVE-2026-50060

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-11T13:18:58.447

Modified: 2026-08-11T13:18:58.447

Link: CVE-2026-50060

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T01:00:03Z

Weaknesses