Description
An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.
Published: 2026-08-27
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Improper Authorization flaw in 3DPassport within Dassault Systèmes 3DSwymer can enable an attacker to access user accounts. The vulnerability is defined by CWE‑285 and can lead to unauthorized use of account credentials, potentially granting the attacker further privileges within the system.

Affected Systems

Dassault Systèmes 3DSwymer for releases 3DEXPERIENCE R2023x, R2024x, R2025x, and R2026x are impacted. No older or newer releases are listed as affected.

Risk and Exploitability

The CVSS score of 9.3 highlights severe risk, and an EPSS score is not provided. The flaw is not listed in the CISA KEV catalog. The vulnerability can be exercised by accessing the 3DPassport component over the network, likely from a compromised or malicious user or from within an attacker’s internal network. The attack requires the ability to reach the 3DPassport service and does not explicitly require privilege escalation, meaning attackers with network access could exploit it. Given the high CVSS and lack of mitigation, the potential impact remains high.

Generated by OpenCVE AI on August 27, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch or upgrade to a release newer than 3DEXPERIENCE R2026x.
  • Restrict network access to the 3DPassport endpoints to only trusted hosts or networks.
  • Enforce least‑privilege and strong authentication policies for all user accounts interacting with 3DPassport.

Generated by OpenCVE AI on August 27, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.
Title Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: 3DS

Published:

Updated: 2026-08-27T14:11:33.949Z

Reserved: 2026-07-20T10:11:24.249Z

Link: CVE-2026-16279

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T17:17:14.460

Modified: 2026-08-27T17:17:14.460

Link: CVE-2026-16279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T17:30:12Z

Weaknesses