CVE-2026-4681 PUBLISHED

Critical Remote Code Execution vulnerability reported in Windchill

Assigner: PTC
Reserved: 23.03.2026 Published: 23.03.2026 Updated: 24.03.2026

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0; FlexPLM: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/AU:Y/R:U/V:C/RE:M/U:Red
CVSS Score: 9.3

Product Status

Vendor PTC
Product Windchill PDMLink
Versions Default: unknown
  • Version 11.0 M030 is affected
  • Version 11.1 M020 is affected
  • Version 11.2.1.0 is affected
  • Version 12.0.2.0 is affected
  • Version 12.1.2.0 is affected
  • Version 13.0.2.0 is affected
  • Version 13.1.0.0 is affected
  • Version 13.1.1.0 is affected
  • Version 13.1.2.0 is affected
  • Version 13.1.3.0 is affected
Vendor PTC
Product FlexPLM
Versions Default: unknown
  • Version 11.0 M030 is affected
  • Version 11.1 M020 is affected
  • Version 11.2.1.0 is affected
  • Version 12.0.0.0 is affected
  • Version 12.0.2.0 is affected
  • Version 12.0.3.0 is affected
  • Version 12.1.2.0 is affected
  • Version 12.1.3.0 is affected
  • Version 13.0.2.0 is affected
  • Version 13.0.3.0 is affected

References

Problem Types

  • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE

Impacts

  • CAPEC-242 Code Injection