VYPR
advisoryPublished Sep 22, 2026· 1 source

Critical Authentication Bypass in Siemens Industrial Edge Management Allows Account Takeover

A critical authentication bypass vulnerability in Siemens Industrial Edge Management enables unauthenticated remote attackers to reset user credentials without verification, leading to full account takeover.

Siemens Industrial Edge Management (IEM) is facing a critical security vulnerability, identified as CVE-2026-18963, that allows unauthenticated remote attackers to bypass standard security protocols and gain complete control over user accounts. The flaw resides in the product's credential reset mechanism, specifically within the keycloak-services component responsible for identity and access management.

Exploitation of this vulnerability allows an attacker to initiate a password reset for any user without requiring the usual email verification step. By manipulating the reset flow, an attacker can directly set new credentials for a targeted account, effectively achieving a full account takeover. This bypass poses a significant risk, as it circumvents fundamental security checks designed to protect user access.

The vulnerability affects multiple versions of Siemens Industrial Edge Management, including Industrial Edge Management Cloud (all versions), Industrial Edge Management Pro V1 (versions between 1.14.9 and 1.15.20), Industrial Edge Management Pro V2 (versions between 2.2.0 and 2.2.2), and Industrial Edge Management Virtual (versions between 2.6.0 and 2.9.1). The widespread impact across different deployment models underscores the urgency for users to address this issue.

Siemens has acknowledged the severity of the vulnerability, assigning it a CVSS v3 base score of 9.1 (Critical). The Common Vulnerability Scoring System details highlight the attack vector as Network (AV:N), with low attack complexity (AC:L), no privileges required (PR:N), no user interaction needed (UI:N), and a scope of Unchanged (S:U). The impact on Confidentiality, Integrity, and Availability is High (C:H/I:H/A:N).

To mitigate this risk, Siemens recommends several strategies. The most effective immediate measure is to block direct internet access to IEM Pro or IEM Virtual instances. If complete blocking is not feasible, organizations can configure a Web Application Firewall (WAF) or a Reverse Proxy to block the specific path /auth/realms/customer/login-actions/reset-credentials. Alternatively, the password reset functionality can be deactivated directly within the Keycloak realm settings by setting 'Forgot password' to 'Off'.

Siemens has released updated versions for the affected products to address the vulnerability. Users are strongly advised to update to the latest versions: V1.15.20 or later for Industrial Edge Management Pro V1, V2.2.2 or later for Industrial Edge Management Pro V2, and V2.9.1 or later for Industrial Edge Management Virtual. These updates contain the necessary fixes to close the authentication bypass loophole.

CISA has also issued an advisory, urging organizations to implement defensive measures to minimize exploitation risks. These include minimizing network exposure of control system devices, ensuring they are not accessible from the internet, and locating them behind firewalls, isolated from business networks. Secure remote access methods like VPNs should be used, with the caveat that VPNs themselves must be kept updated.

This critical vulnerability in Siemens Industrial Edge Management highlights the ongoing challenges in securing industrial control systems and edge computing environments. The ability for unauthenticated attackers to bypass credential recovery mechanisms underscores the need for robust security practices, including regular patching, network segmentation, and vigilant monitoring of access controls.

Synthesized by Vypr AI