Description
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
Published: 2026-08-11
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds read that occurs while Solid Edge parses specially crafted PAR files. This flaw is a CWE‑125 weakness and, when triggered, can give an attacker the ability to execute arbitrary code within the context of the Solid Edge process. The primary impact is the potential compromise of confidentiality, integrity, and availability of the affected system.

Affected Systems

Affected vendors and products include Siemens Solid Edge SE2025, all versions prior to V225.0 Update 15, and Siemens Solid Edge SE2026, all versions prior to V226.0 Update 7. These versions may be running in environments such as design teams or manufacturing systems where Solid Edge is used for 3‑D modeling.

Risk and Exploitability

The CVSS base score is 7.3, indicating a high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the execution of a malicious PAR file that an attacker can provide to a user running Solid Edge. The exploit requires the user to open or process a crafted file, so it is primarily a local threat that can happen via a social‑engineering attack or compromised file distribution. The impact, if successful, is high because it allows arbitrary code execution in the user’s session.

Generated by OpenCVE AI on August 11, 2026 at 23:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Siemens Solid Edge update that includes the fix for the out-of-bounds read issue.
  • Verify that any PAR files opened by Solid Edge come from trusted and authenticated sources, and refrain from opening unknown or unverified files.
  • If the software configuration allows, restrict Solid Edge’s automatic parsing of PAR files or adjust document‑level security settings to prevent the processing of potentially malicious content.

Generated by OpenCVE AI on August 11, 2026 at 23:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens solid Edge Se2025
Siemens solid Edge Se2026
Vendors & Products Siemens
Siemens solid Edge Se2025
Siemens solid Edge Se2026

Tue, 11 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Solid Edge PAR File Parsing Enables Code Execution

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Solid Edge Se2025 Solid Edge Se2026
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-11T14:51:32.795Z

Reserved: 2026-06-03T11:07:02.668Z

Link: CVE-2026-50063

cve-icon Vulnrichment

Updated: 2026-08-11T14:51:22.945Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T13:18:58.860

Modified: 2026-08-28T19:03:37.837

Link: CVE-2026-50063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T23:30:05Z

Weaknesses