Skip to content

Security1 publisher2 min readPublished

Crafted Desigo CC graphics documents execute code on the operator client that opens them

CVE-2026-34223 lets a script embedded in a user-defined graphics document write arbitrary files on any Desigo CC V6 or V7 client. Siemens has no fix and points operators at who is allowed to open graphics.

The Watch · Security desk

Illustration accompanying Crafted Desigo CC graphics documents execute code on the operator client that opens them

What happened

  • CISA published an advisory for CVE-2026-34223, a client code execution flaw in Siemens Desigo CC that runs arbitrary code on client devices through specially crafted graphics documents.
  • Every version of the Desigo CC V6 and V7 families is listed as affected, with both families recorded under the same CVE.
  • Siemens has no fix available and offers one mitigation, an authorization policy review for the Graphics application under least privilege.
  • Michelin CERT reported the vulnerability to Siemens, and CISA cites insufficient input validation of scripts in user-defined graphics as the root cause.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The target is the operator workstation itself, and Siemens says compromise of the client operating system could be followed by lateral movement inside the organization.
  • constraint With no fixed release of either family, the work moves from patch management to per-site permissions on who may open and configure graphics.
  • decision Sites that accept graphics pages from integrators or shared project libraries now have to decide whether to treat those files as executable content and review them before an operator displays one.
  • capability Segmentation and firewalls miss this path, because the delivery step is a file a privileged user opens on a console that already sits inside the protected zone.

Desigo CC projects contain user-defined graphics, and those graphics can carry embedded scripts. CISA's advisory describes the fault as insufficient input validation when the client handles those scripts [3]. A script designed or modified by an attacker executes on the client application instance when a user opens the document, and it can write arbitrary files to the client's operating system [4].

Two conditions have to hold. The attacker crafts the graphics document, and a user with sufficient privileges displays it [5]. Siemens' countermeasure addresses who may touch graphics configuration at all: "Evaluate authorization policy for Graphics application following Least Privilege principle, so only required users have access to the configuration," the advisory says [7].

One identifier, CVE-2026-34223, covers both the V6 and V7 families, and both are listed as all versions affected [1][2], so no release of either family sits outside the scope [8]. "Currently no fix is available," the advisory says [6]. CISA published it without a CVSS score [12]. Siemens carries the same issue as SSA-330084 [15].

The claimed impact is bounded: compromise of the client operating system and potential lateral movement within the organization [13]. The advisory reports no exploitation, and it stops short of tracing a route from an operator console to a named corporate system [14]. Desigo CC clients are workstations that engineers and operators sit at during a shift, so the step from client to file system to network is the ordinary one.

CISA's standing guidance attached to the advisory is network hygiene: keep control system devices off the internet, put them behind firewalls, isolate them from business networks, and use VPNs where remote access is required [11]. None of that stops an operator opening a graphics document someone else put in the project. The control that matches this flaw is the authorization review Siemens describes, carried out site by site.

Michelin CERT reported the vulnerability to Siemens [9]. Desigo CC is deployed worldwide, and CISA lists its sectors as critical manufacturing and commercial facilities [10].

What to watch

  • An update to Siemens advisory SSA-330084 naming a fixed version for V6 or V7, which would replace the permissions workaround.
  • Any CVSS score or first report of exploitation attached to CVE-2026-34223.
  • Whether Siemens ships an option to stop clients executing scripts embedded in graphics documents, instead of gating who may open them.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories