Description
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Published: 2026-08-11
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Solid Edge SE2025 and SE2026 applications contain a use‑after‑free vulnerability that can be triggered while parsing specially crafted DFT files. Exploitation of this flaw allows an attacker to execute arbitrary code within the context of the running application, potentially compromising confidentiality, integrity, and availability of the host system.

Affected Systems

The vulnerability affects Siemens Solid Edge SE2025 versions earlier than V225.0 Update 15 and Solid Edge SE2026 versions earlier than V226.0 Update 7. Users of these older releases are susceptible if they open or process malicious DFT files.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity level, though no EPSS score is available and the issue is not listed in CISA KEV. The likely attack vector is that an attacker provides a malicious DFT file to a user running Solid Edge, which may be local or remote if the file is transmitted over a network or shared repository. Given the use‑after‑free nature, exploitation requires successful parsing of the file and proper memory handling, so observed exploit activity is expected to be moderate unless the vulnerability is actively leveraged.

Generated by OpenCVE AI on August 11, 2026 at 23:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued update that removes the use‑after‑free flaw (upgrade to Solid Edge SE2025 V225.0 Update 15 or newer, or Solid Edge SE2026 V226.0 Update 7 or newer).
  • Restrict the import of DFT files to trusted sources or use file‑type validation checks to prevent malicious content from being processed.
  • Monitor DFT file processing events and disable DFT import in unpatched installations until a patch is available.

Generated by OpenCVE AI on August 11, 2026 at 23:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Vulnerability in Solid Edge Allowing Code Execution via Malicious DFT Files
First Time appeared Siemens
Siemens solid Edge Se2025
Siemens solid Edge Se2026
Vendors & Products Siemens
Siemens solid Edge Se2025
Siemens solid Edge Se2026

Tue, 11 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Solid Edge Se2025 Solid Edge Se2026
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-11T14:00:55.110Z

Reserved: 2026-06-03T11:07:02.668Z

Link: CVE-2026-50061

cve-icon Vulnrichment

Updated: 2026-08-11T14:00:52.458Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T13:18:58.583

Modified: 2026-08-28T19:03:37.837

Link: CVE-2026-50061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T00:00:03Z

Weaknesses