news.mlab.sh
Back to the feed
vulnerability

Siemens Industrial Edge Management

CriticalCVSS 9.1
Summary

A critical authentication bypass vulnerability exists in Siemens Industrial Edge Management, allowing an unauthenticated attacker to force a password reset and gain full control over user accounts. Siemens has released updates to address this issue, and CISA recommends immediate action to mitigate the risk. The vulnerability stems from a flaw within the Keycloak-services component, a core identity and access management engine.

Siemens Industrial Edge Management contains an authentication bypass vulnerability (CVE-2026-18963) that could allow an unauthenticated remote attacker to perform a full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions. The vulnerability is located within the reset-credentials flow of the keycloak-services component, a core engine for identity and access management in Red Hat Build of Keycloak. This flaw enables an attacker to force the password reset process for any user without needing to click the required email verification link, ultimately leading to full control over target user accounts.

The following versions of Siemens Industrial Edge Management are affected:

  • Industrial Edge Management Cloud vers:all/* (CVE-2026-18963)
  • Industrial Edge Management Pro V1 vers:intdot/>=1.14.9|<1.15.20 (CVE-2026-18963)
  • Industrial Edge Management Pro V2 vers:intdot/>=2.2.0|<2.2.2 (CVE-2026-18963)
  • Industrial Edge Management Virtual vers:intdot/>=2.6.0|<2.9.1 (CVE-2026-18963)

Background: The vulnerability is deployed worldwide and is associated with Siemens’ headquarters in Germany.

Remediation: Siemens strongly recommends blocking direct internet access to IEM Pro / IEM Virtual. Additionally, a Web Application Firewall (WAF) or Reverse Proxy should be configured to block the path: /auth/realms/customer/login-actions/reset-credentials. Alternatively, deactivate the password reset functionality directly within the Keycloak realm settings: Identity & access management > realm settings > Login > Forgot password > Off. Updates to V1.15.20 or later, V2.2.2 or later, and V2.9.1 or later are available at https://iehub.eu1.edge.siemens.cloud/.

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities, including minimizing network exposure for all control system devices, locating control system networks behind firewalls, and utilizing more secure remote access methods like VPNs (while recognizing VPN vulnerabilities). Organizations should perform proper impact analysis and risk assessment prior to deploying defensive measures and report suspected malicious activity to CISA.

Read the full article at CISA Advisories