Update affected products to the minimum patched versions: SIMOVE Fleetmanager V3.1.13 or later, V3.2.4 or later, V3.3.2 or later, or V4.0.1 or later. SIPLANT V3.1.4 or later. Restrict network access to affected devices behind firewalls. Implement user management to limit services' access rights to project files. Isolate control system networks from business networks per Siemens operational guidelines.
Quick answers
What is CVE-2026-67367?
Update affected products to the minimum patched versions: SIMOVE Fleetmanager V3.1.13 or later, V3.2.4 or later, V3.3.2 or later, or V4.0.1 or later. SIPLANT V3.1.4 or later. Restrict network access to affected devices behind firewalls. Implement user management to limit services' access rights to project files. Isolate control system networks from business networks per Siemens operational guidelines.
How severe is CVE-2026-67367?
high, CVSS 8.6
Is CVE-2026-67367 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-67367 be mitigated?
Update affected products to the minimum patched versions: SIMOVE Fleetmanager V3.1.13 or later, V3.2.4 or later, V3.3.2 or later, or V4.0.1 or later. SIPLANT V3.1.4 or later. Restrict network access to affected devices behind firewalls. Implement user management to limit services' access rights to project files. Isolate control system networks from business networks per Siemens operational guidelines.
CVSS
8.6
Vendor
Siemens
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
SIMOVE Fleetmanager, SIPLANT
Mitigation
Update affected products to the minimum patched versions: SIMOVE Fleetmanager V3.1.13 or later, V3.2.4 or later, V3.3.2 or later, or V4.0.1 or later. SIPLANT V3.1.4 or later. Restrict network access to affected devices behind firewalls. Implement user management to limit services' access rights to project files. Isolate control system networks from business networks per Siemens operational guidelines.
Siemens has disclosed a critical path traversal vulnerability (CVE-2026-67367) affecting SIMOVE Fleetmanager and SIPLANT industrial software platforms. The flaw resides in the embedded HTTP server's file-serving endpoint, which fails to properly validate directory traversal sequences. An unauthenticated, remote attacker could exploit this to read arbitrary files from the underlying operating system, potentially exposing credential stores, private keys, and configuration secrets. Siemens has released updated versions and advisories to address the issue.