Description
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
Published: 2026-08-11
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Solid Edge SE2025 and SE2026 contain an out‑of‑bounds read when parsing specially crafted PAR files. The flaw, classified as CWE‑125, can lead to execution of code in the context of the current process. An attacker who can provide a malicious PAR file (for example via local file selection or a compromised installation package) gains the authority of the user running Solid Edge.

Affected Systems

The vulnerability affects Siemens Solid Edge SE2025 in all versions older than V225.0 Update 15 and Siemens Solid Edge SE2026 in all versions older than V226.0 Update 7. These build identifiers correspond to the product releases that have not applied the out‑of‑bounds read fix.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity. No EPSS score is available, so the current exploitation probability cannot be quantified. The weakness is not present in the CISA KEV catalog. Exploitation requires a specially crafted PAR file to be parsed by Solid Edge, which typically means the attack vector is local or requires a privileged user to open the file. This makes the threat meaningful for environments where malicious files can be introduced, such as shared networks or compromised devices.

Generated by OpenCVE AI on August 11, 2026 at 23:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Solid Edge SE2025 to version V225.0 Update 15 or later.
  • Upgrade Solid Edge SE2026 to version V226.0 Update 7 or later.
  • Avoid opening unknown or untrusted PAR files until the update is applied.
  • Check Siemens security advisories for the latest patches.

Generated by OpenCVE AI on August 11, 2026 at 23:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Solid Edge PAR File Parsing Allowing Code Execution
First Time appeared Siemens
Siemens solid Edge Se2025
Siemens solid Edge Se2026
Vendors & Products Siemens
Siemens solid Edge Se2025
Siemens solid Edge Se2026

Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Solid Edge Se2025 Solid Edge Se2026
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-11T12:20:18.621Z

Reserved: 2026-06-03T11:07:02.668Z

Link: CVE-2026-50062

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-11T13:18:58.720

Modified: 2026-08-11T13:18:58.720

Link: CVE-2026-50062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T00:00:03Z

Weaknesses