Publication Date:
Last Update:
Current Version: V1.0
CVSS v3.1 Base Score: 9.1
Un-/Collapse All
Affected Product and Versions Remediation

All versions
affected by CVE-2026-18963
Vulnerability mitigated with firewall rules on 2026-08-26 and fixed with update on 2026-09-02; no user actions necessary


All versions >= V1.14.9 < V1.15.20
affected by CVE-2026-18963
Update to V1.15.20 or later version



All versions >= V2.2.0 < V2.2.2
affected by CVE-2026-18963
Update to V2.2.2 or later version



All versions >= V2.6.0 < V2.9.1
affected by CVE-2026-18963
Update to V2.9.1 or later version


  • Configure a Web Application Firewall (WAF) or Reverse Proxy
    If complete blocking of internet access is not immediately feasible, you can use a Web Application Firewall (WAF) or a Reverse Proxy to block the affected path. Please configure your WAF or Reverse Proxy to block the following path:
    /auth/realms/customer/login-actions/reset-credentials
    Please note that by blocking this path, the password reset functionality will be unavailable.

  • Block direct internet access to IEM Pro / IEM Virtual
    The most effective immediate measure is to block direct internet access to your IEM Pro or IEM V instance. This ensures that no external attacks can occur via this vulnerability.

  • Deactivate Password Reset in Keycloak Realm Settings
    Deactivate the password reset functionality directly within the Keycloak realm settings. To do this, navigate to:
    Identity & access management > realm settings > Login > Forgot password > Off
    Please note that by deactivating this setting, the password reset functionality will be unavailable.

Product-specific remediations or mitigations can be found in the section Known Affected Products.
Please follow the General Security Recommendations.

As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity

Un-/Collapse All

This chapter describes all vulnerabilities (CVE-IDs) addressed in this security advisory. Wherever applicable, it also documents the product-specific impact of the individual vulnerabilities.

CVSS v3.1 Base Score 9.1
CVSS v3.1 Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE CWE-640: Weak Password Recovery Mechanism for Forgotten Password

https://www.siemens.com/cert/advisories
V1.0 (2026-09-08): Publication Date