A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.
The following versions of Siemens Desigo CC family are affected:
Desigo CC family V6 vers:all/* (CVE-2026-34223)
Desigo CC family V7 vers:all/* (CVE-2026-34223)
Vendor
Equipment
Siemens
Siemens Desigo CC family
Improper Control of Generation of Code ('Code Injection')