View CSAF Summary A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization. The following versions of Siemens Desigo CC family are affected: Desigo CC family V6 vers:all/* (CVE-2026-34223) Desigo CC family V7 vers:all/* (CVE-2026-34223) CVSS Vendor Equipment Vulnerabilities v3 8.2 Siemens Siemens Desigo CC family Improper Control of Generation of Code ('Code Injection') Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-34223 The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, w…
Open the source record- Tags
- CISA
- Related exam domains
- CISSP 3: Security Architecture and Engineering; CISSP 8: Software Development Security; CISM 2: Information Security Risk Management; CISM 3: Information Security Program
- Source record id
- /node/25525
- First seen by InfoSec Signals
- 9/23/2026
Exam domain labels come from a keyword heuristic and are study hints, not an official mapping. The summary is the publisher's own text, shortened; the linked record is authoritative.