Password reset flaw hands over Siemens Edge accounts

Published

Ask Siemens Industrial Edge Management to reset a user's password and, on unpatched versions, it will let you set a new one without ever clicking the verification link it emails out. That is enough to take over any account on the platform, including an administrator's, and it needs no credentials to start.

The flaw is CVE-2026-18963, rated 9.1, and it is not really Siemens' own bug. It sits in the reset-credentials flow of keycloak-services, the identity engine from the Red Hat build of Keycloak that Industrial Edge Management embeds. CISA published the advisory on 22 September as one of six Siemens advisories issued the same day.

What an Edge Management account is worth

Industrial Edge Management is the console that pushes applications and configuration to edge devices on a plant floor, so an account on it is not a login to a reporting tool. Siemens lists Industrial Edge Management Cloud in all versions as affected, Pro V1 from 1.14.9 to below 1.15.20, Pro V2 from 2.2.0 to below 2.2.2, and Virtual from 2.6.0 to below 2.9.1.

Customers on the hosted version are already covered. Siemens states it mitigated the cloud instance with firewall rules on 26 August and fixed it with an update on 2 September, with no action required from users. Everyone running Pro or Virtual on their own infrastructure has to move themselves.

Block one URL path if you cannot patch today

Update to 1.15.20, 2.2.2 or 2.9.1 through the Siemens Industrial Edge hub. Where that has to wait, Siemens gives three interim options, in its own order of preference: cut direct internet access to the instance, which it calls the most effective immediate measure; or put a web application firewall or reverse proxy in front of it and block the path /auth/realms/customer/login-actions/reset-credentials; or turn password reset off inside Keycloak under realm settings, login, forgot password. The last two disable password resets for legitimate users as well, which is the trade being offered.

Five more Siemens advisories the same day

The rest of the batch, ordered by severity:

Siemens ProductCERT is named as the reporter on the Industrial Edge Management, Siveillance Control, SIMOVE and WTV676 advisories, with Desigo CC credited to Michelin CERT. None of the advisories reports known public exploitation.

The Industrial Edge Management entry is the one to act on first, and it is worth noting why: it is the only one in the batch where the vulnerable component came from somewhere else. A plant operator patching Siemens kit this week is, in that one case, patching Keycloak. Our coverage of AI-assisted probing of Siemens S7 controllers covers the other end of the same estate.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Detection coverage

Read the full analysis on IntelFusions