Siemens has released a security update to address vulnerabilities in the Element maps-ng product.
The affected products are Element maps-ng versions prior to V47.12.3, Element maps-ng versions prior to V48.11.3, And Element maps-ng versions prior to V49.16.1.
The vulnerability is an XSS vulnerability (a vulnerability that allows malicious scripts to be injected into web pages) caused by insufficient input sanitization when generating web pages in the si-map component of Element maps-ng.
The identifier for this vulnerability is CVE-2026-66155, and its CVSS score is 7.6.
Siemens released a Vulnerability Patch via an update on August 27, 2026.
The patched versions are Element maps-ng V47.12.3 And later, Element maps-ng V48.11.3 And later, and Element maps-ng V49.16.1 And later.