Description
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.
Published: 2026-08-11
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds write that occurs while parsing specially crafted PSM files, which can lead to arbitrary code execution in the context of the current process. The flaw allows an attacker to provide a malicious file that triggers the vulnerability and gains the privileges of the running Solid Edge application.

Affected Systems

The issue affects Siemens Solid Edge SE2025 in all versions prior to V225.0 Update 15 and Solid Edge SE2026 in all versions prior to V226.0 Update 7. Users of these unpatched versions are at risk.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attack vector is an attacker who can supply a crafted PSM file, either through user interaction or a compromised file source. The vulnerability may be exploited locally, requiring the victim to open or process the malicious file.

Generated by OpenCVE AI on August 11, 2026 at 23:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Siemens Solid Edge SE2025 Update 15 or later to remediate the flaw.
  • Apply Siemens Solid Edge SE2026 Update 7 or later to remediate the flaw.
  • If remediation is not immediately available, restrict access to PSM files for untrusted users and monitor system logs for suspicious activity.

Generated by OpenCVE AI on August 11, 2026 at 23:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens solid Edge Se2025
Siemens solid Edge Se2026
Vendors & Products Siemens
Siemens solid Edge Se2025
Siemens solid Edge Se2026

Wed, 12 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in SOLID Edge PSM Parser Allows RCE

Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Solid Edge Se2025 Solid Edge Se2026
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-11T18:08:15.586Z

Reserved: 2026-06-03T11:07:02.668Z

Link: CVE-2026-50064

cve-icon Vulnrichment

Updated: 2026-08-11T18:08:10.747Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T13:18:58.990

Modified: 2026-08-28T19:03:37.837

Link: CVE-2026-50064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T00:00:03Z

Weaknesses