CISA has warned of a critical authentication bypass in Siemens Industrial Edge Management that could enable an unauthenticated remote attacker to take over user accounts. Tracked as CVE-2026-18963, the flaw affects the reset-credentials process in the Keycloak identity and access management component. An attacker can trigger a password reset without completing the required email verification, then set new credentials directly. The vulnerability has a CVSS 3.1 score of 9.1 and is classified as critical, with impacts on confidentiality and integrity.
Affected products are Industrial Edge Management Cloud (all versions), Pro V1 versions 1.14.9 to before 1.15.20, Pro V2 versions 2.2.0 to before 2.2.2, and Virtual versions 2.6.0 to before 2.9.1. Siemens has issued fixes: users should update Pro V1 to 1.15.20 or later, Pro V2 to 2.2.2 or later, and Virtual to 2.9.1 or later. Siemens says the cloud service was mitigated with firewall rules on 26 August 2026 and fixed through an update on 2 September 2026, with no user action required. The advisory does not report confirmed exploitation.
Until updates are applied, Siemens recommends blocking direct internet access to IEM Pro and IEM Virtual. Where that is not possible, a web application firewall or reverse proxy can block `/auth/realms/customer/login-actions/reset-credentials`, although this disables password resets. Administrators can also turn off password recovery in the Keycloak realm settings.