Siemens Solid Edge Uninitialized Pointer Access Vulnerability Allowing Code Execution

Vulnerability

A vulnerability exists in Siemens Solid Edge SE2026, all versions prior to V226.0 Update 5, due to uninitialized pointer access when parsing specially crafted PAR files. This vulnerability could be exploited to execute code in the context of the current process.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution in the context of the current process.

Remediation

Users are advised to update Solid Edge SE2026 to V226.0 Update 5 or a later version. Additional information can be found on the Siemens Support website.

Added: May 12, 2026, 10:26 AM
Updated: May 12, 2026, 10:26 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
3.6
remediation
7.7
relevance
7.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.