Input validation error in Windchill and FlexPLM - CVE-2026-12569
Published: June 30, 2026
Windchill
FlexPLM
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to an insufficient issue. A remote non-authenticated attacker can send a specially crafted HTTP POST request to the "Windchill/login/*.jsp" endpoint and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.