CVE-2026-23715 is an out-of-bounds write vulnerability affecting Siemens Simcenter Femap and Simcenter Nastran (all versions prior to V2512). An attacker could exploit this by crafting a malicious XDB file, leading to arbitrary code execution in the context of the current process. Rated as HIGH severity (CVSS 7.3), this vulnerability requires local access and user interaction (e.g., opening the malicious file). There is currently no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2512.0000CPE matchmatch criteria | cpe:2.3:a:siemens:simcenter_femap:*:*:*:*:*:*:*:* | ||
< 2512.0000CPE matchmatch criteria | cpe:2.3:a:siemens:simcenter_nastran:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.