{"api_version":"1","generated_at":"2026-07-23T15:17:00+00:00","cve":"CVE-2026-12569","urls":{"html":"https://cve.report/CVE-2026-12569","api":"https://cve.report/api/cve/CVE-2026-12569.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-12569","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-12569"},"summary":{"title":"Remote Code Execution (RCE) vulnerability in Windchill PDMlink","description":"A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.   *  This advisory also applies to all CPS versions\n  *  The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030","state":"PUBLISHED","assigner":"PTC","published_at":"2026-06-18 01:18:12","updated_at":"2026-06-30 18:16:43"},"problem_types":["CWE-20","CWE-502","CWE-20 CWE-20 Improper input validation","CWE-502 CWE-502 Deserialization of untrusted data"],"metrics":[{"version":"4.0","source":"0b655efc-079c-4cb9-9e8d-164871239f4e","type":"Secondary","score":"9.3","severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:X/U:Red","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:X/U:Red","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"YES","Recovery":"USER","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"RED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"9.3","severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/AU:Y/R:U/V:C/U:Red","data":{"Automatable":"YES","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"RED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/AU:Y/R:U/V:C/U:Red","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"}},{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}}],"references":[{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-12569","name":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-12569","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.ptc.com/en/support/article/CS473270","name":"https://www.ptc.com/en/support/article/CS473270","refsource":"0b655efc-079c-4cb9-9e8d-164871239f4e","tags":["Permissions Required"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-12569","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12569","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"PTC","product":"Windchill PDMLink","version":"affected 11.0 M030 semver","platforms":[]},{"source":"CNA","vendor":"PTC","product":"Windchill PDMLink","version":"affected 11.1 M020","platforms":[]},{"source":"CNA","vendor":"PTC","product":"Windchill PDMLink","version":"affected 11.2.1.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"Windchill PDMLink","version":"affected 12.0.2.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"Windchill PDMLink","version":"affected 12.1.2.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"Windchill PDMLink","version":"affected 13.0.2.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"Windchill PDMLink","version":"affected 13.1.0.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"Windchill PDMLink","version":"affected 13.1.1.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"Windchill PDMLink","version":"affected 13.1.2.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"Windchill PDMLink","version":"affected 13.1.3.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"FlexPLM","version":"affected 11.0 M030 semver","platforms":[]},{"source":"CNA","vendor":"PTC","product":"FlexPLM","version":"affected 11.1 M020","platforms":[]},{"source":"CNA","vendor":"PTC","product":"FlexPLM","version":"affected 11.2.1.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"FlexPLM","version":"affected 12.0.0.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"FlexPLM","version":"affected 12.0.2.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"FlexPLM","version":"affected 12.1.2.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"FlexPLM","version":"affected 12.1.3.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"FlexPLM","version":"affected 13.0.2.0","platforms":[]},{"source":"CNA","vendor":"PTC","product":"FlexPLM","version":"affected 13.0.3.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"flexplm","cpe6":"11.1m020","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"flexplm","cpe6":"11.2.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"flexplm","cpe6":"12.0.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"flexplm","cpe6":"12.0.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"flexplm","cpe6":"12.1.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"flexplm","cpe6":"13.0.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"flexplm","cpe6":"13.0.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"11.0m030","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"flexplm","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"windchill_pdmlink","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"windchill_pdmlink","cpe6":"11.0m030","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"windchill_pdmlink","cpe6":"11.1m020","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"windchill_pdmlink","cpe6":"11.2.1.0","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"windchill_pdmlink","cpe6":"12.0.2.0","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"windchill_pdmlink","cpe6":"12.1.2.0","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"windchill_pdmlink","cpe6":"13.0.2.0","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"windchill_pdmlink","cpe6":"13.1.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"windchill_pdmlink","cpe6":"13.1.1.0","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"windchill_pdmlink","cpe6":"13.1.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"12569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ptc","cpe5":"windchill_pdmlink","cpe6":"13.1.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2026","cve_id":"12569","cve":"CVE-2026-12569","vendorProject":"PTC","product":"Windchill and FlexPLM","vulnerabilityName":"PTC Windchill and FlexPLM Improper Input Validation Vulnerability","dateAdded":"2026-06-25","shortDescription":"PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","dueDate":"2026-06-28","knownRansomwareCampaignUse":"Unknown","notes":"https://www.ptc.com/en/support/article/CS473270 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-12569","cwes":"CWE-20,CWE-502","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:15"},"epss":{"cve_year":"2026","cve_id":"12569","cve":"CVE-2026-12569","epss":"0.012470000","percentile":"0.661830000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:32"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-12569","options":[{"Exploitation":"active"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-06-26T03:56:12.541322Z","version":"2.0.3"},"type":"ssvc"}},{"other":{"content":{"dateAdded":"2026-06-25","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-12569"},"type":"kev"}}],"providerMetadata":{"dateUpdated":"2026-06-30T17:34:13.458Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-12569"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Windchill PDMLink","vendor":"PTC","versions":[{"lessThanOrEqual":"11.0 M030","status":"affected","version":"0","versionType":"semver"},{"status":"affected","version":"11.1 M020"},{"status":"affected","version":"11.2.1.0"},{"status":"affected","version":"12.0.2.0"},{"status":"affected","version":"12.1.2.0"},{"status":"affected","version":"13.0.2.0"},{"status":"affected","version":"13.1.0.0"},{"status":"affected","version":"13.1.1.0"},{"status":"affected","version":"13.1.2.0"},{"status":"affected","version":"13.1.3.0"}]},{"defaultStatus":"unaffected","product":"FlexPLM","vendor":"PTC","versions":[{"lessThanOrEqual":"11.0 M030","status":"affected","version":"0","versionType":"semver"},{"status":"affected","version":"11.1 M020"},{"status":"affected","version":"11.2.1.0"},{"status":"affected","version":"12.0.0.0"},{"status":"affected","version":"12.0.2.0"},{"status":"affected","version":"12.1.2.0"},{"status":"affected","version":"12.1.3.0"},{"status":"affected","version":"13.0.2.0"},{"status":"affected","version":"13.0.3.0"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.&nbsp;<div><ul><li>This advisory also applies to all CPS versions</li><li>The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030</li></ul></div>"}],"value":"A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.   *  This advisory also applies to all CPS versions\n  *  The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030"}],"impacts":[{"capecId":"CAPEC-586","descriptions":[{"lang":"en","value":"CAPEC-586 Object Injection"}]},{"capecId":"CAPEC-153","descriptions":[{"lang":"en","value":"CAPEC-153 Input Data Manipulation"}]}],"metrics":[{"cvssV4_0":{"Automatable":"YES","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"RED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/AU:Y/R:U/V:C/U:Red","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-20","description":"CWE-20 Improper input validation","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-502","description":"CWE-502 Deserialization of untrusted data","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-18T00:11:35.241Z","orgId":"0b655efc-079c-4cb9-9e8d-164871239f4e","shortName":"PTC"},"references":[{"tags":["vendor-advisory","mitigation","permissions-required"],"url":"https://www.ptc.com/en/support/article/CS473270"}],"source":{"discovery":"UNKNOWN"},"title":"Remote Code Execution (RCE) vulnerability in Windchill PDMlink","x_generator":{"engine":"Vulnogram 1.0.2"}}},"cveMetadata":{"assignerOrgId":"0b655efc-079c-4cb9-9e8d-164871239f4e","assignerShortName":"PTC","cveId":"CVE-2026-12569","datePublished":"2026-06-18T00:11:35.241Z","dateReserved":"2026-06-18T00:02:58.904Z","dateUpdated":"2026-06-30T17:34:13.458Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-18 01:18:12","lastModifiedDate":"2026-06-30 18:16:43","problem_types":["CWE-20","CWE-502","CWE-20 CWE-20 Improper input validation","CWE-502 CWE-502 Deserialization of untrusted data"],"metrics":{"cvssMetricV40":[{"source":"0b655efc-079c-4cb9-9e8d-164871239f4e","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:X/U:Red","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"YES","Recovery":"USER","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"RED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-26T03:56:12.541322Z","id":"CVE-2026-12569","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:flexplm:*:*:*:*:*:*:*:*","versionEndIncluding":"11.0m030","matchCriteriaId":"9645DC27-47FD-4E68-A73F-380DE6AB9265"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:flexplm:11.1m020:*:*:*:*:*:*:*","matchCriteriaId":"1BA9771B-C606-4B0D-ADF1-E0BEA4FD5407"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:flexplm:11.2.1.0:*:*:*:*:*:*:*","matchCriteriaId":"AF4D5C35-1E36-4A6E-86AA-5E26F5375E84"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:flexplm:12.0.0.0:*:*:*:*:*:*:*","matchCriteriaId":"2A5BC13C-CBF4-4EA8-B5B7-E680BF7B22DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:flexplm:12.0.2.0:*:*:*:*:*:*:*","matchCriteriaId":"0A7DB804-FA55-456C-8C58-7ACBDA710F45"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:flexplm:12.1.3.0:*:*:*:*:*:*:*","matchCriteriaId":"AABF3817-5BA7-4604-92D3-468B73EEDA75"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:flexplm:13.0.2.0:*:*:*:*:*:*:*","matchCriteriaId":"33798622-E630-4F62-B675-01BFC99E73CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:flexplm:13.0.3.0:*:*:*:*:*:*:*","matchCriteriaId":"5D992EFD-F674-4217-9078-FAD2558168D5"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:windchill_pdmlink:*:*:*:*:*:*:*:*","versionEndExcluding":"11.0m030","matchCriteriaId":"A8E8CEE8-BECD-4D33-B14F-BA015EF0E39F"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:windchill_pdmlink:11.0m030:-:*:*:*:*:*:*","matchCriteriaId":"C456B19A-8A53-47AA-8C44-D7E4A99D73D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:windchill_pdmlink:11.1m020:-:*:*:*:*:*:*","matchCriteriaId":"6B33DB9C-7883-495B-ACFF-31422ED4A256"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:windchill_pdmlink:11.2.1.0:-:*:*:*:*:*:*","matchCriteriaId":"631EB791-4C82-4A73-8793-465576C47EC2"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:windchill_pdmlink:12.0.2.0:-:*:*:*:*:*:*","matchCriteriaId":"5AAE2484-F8D6-4842-93E3-EAA12469B800"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:windchill_pdmlink:12.1.2.0:-:*:*:*:*:*:*","matchCriteriaId":"FC145374-1ABE-4067-9649-EEE6D031C139"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:windchill_pdmlink:13.0.2.0:-:*:*:*:*:*:*","matchCriteriaId":"925FF6A1-A0A0-4B0F-878A-53CE23ECF2D3"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:windchill_pdmlink:13.1.0.0:*:*:*:*:*:*:*","matchCriteriaId":"D9658DCC-7527-4BDE-BEC1-D5C43A7C7B83"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:windchill_pdmlink:13.1.1.0:-:*:*:*:*:*:*","matchCriteriaId":"6619674F-DABA-420B-88BC-0CFDF2972309"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:windchill_pdmlink:13.1.2.0:*:*:*:*:*:*:*","matchCriteriaId":"0FF72930-943F-4A01-BC2A-6AEACBD38908"},{"vulnerable":true,"criteria":"cpe:2.3:a:ptc:windchill_pdmlink:13.1.3.0:*:*:*:*:*:*:*","matchCriteriaId":"AD29599D-F30B-4664-A8F7-59C256ABAB61"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"12569","Ordinal":"1","Title":"Remote Code Execution (RCE) vulnerability in Windchill PDMlink","CVE":"CVE-2026-12569","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"12569","Ordinal":"1","NoteData":"A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.   *  This advisory also applies to all CPS versions\n  *  The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030","Type":"Description","Title":"Remote Code Execution (RCE) vulnerability in Windchill PDMlink"}]}}}