Machine-generated analysis · WAYSCloud LLM
Siemens Industrial Edge Management versions prior to 1.15.20, 2.2.2, and 2.9.1 are vulnerable to an unauthenticated credential reset (CVE-2026-18963). Siemens recommends updating to the latest releases to remediate the issue.
Context
Siemens Industrial Edge Management is offered as Cloud, Pro V1, Pro V2, and Virtual editions. The advisory states that an authentication bypass in the keycloak-services component allows an unauthenticated remote attacker to reset any user’s password without completing email verification, resulting in full account takeover. The vulnerability carries a CVSS score of 9.1 and is classified as a weak password recovery mechanism. Siemens has released new versions for the affected products and advises updating.
Operator considerations
Check: Verify the installed version of each Industrial Edge Management edition against the affected version ranges.
Isolate: Block direct internet access to IEM Pro and IEM Virtual instances.
Patch: Apply the latest Siemens-released updates for the Cloud, Pro, and Virtual editions.
Log: Monitor for unexpected password reset requests or credential changes.
Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Industrial Edge Management are affected:
Industrial Edge Management Cloud vers:all/* (CVE-2026-18963)
Industrial Edge Management Pro V1 vers:intdot/>=1.14.9|=2.2.0|=2.6.0|= V1.14.9 < V1.15.20, Industrial Edge Management Pro V2 >= V2.2.0 < V2.2.2, Industrial Edge Management Virtual >= V2.6.0 < V2.9.1
MitigationBlock direct internet access to IEM Pro / IEM Virtual The most effective immed...
Read the full advisory on CISA →