Description
A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.
Published: 2026-08-20
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A critical access‑control bypass has been identified in PTC Windchill Risk and Reliability Enterprise Edition. The flaw permits an attacker to gain unauthorized access to protected functions or data that should be restricted. The weakness is consistent with missing authentication checks for sensitive functions (CWE‑306) and the accidental exposure of security credentials (CWE‑620), potentially allowing the attacker to retrieve or modify confidential risk data.

Affected Systems

Windchill Risk and Reliability Enterprise Edition (formerly Relex) – PTC. The CVE does not specify impacted revisions or patch levels. Administrators should verify whether their installations are on the susceptible version series.

Risk and Exploitability

The CVSS score of 9.3 marks this flaw as critical, and the absence of an EPSS score means current exploitation likelihood is unknown but should be treated as high. The vulnerability is listed outside of the CISA KEV catalog. Likely exploitation would occur via remote web interfaces where the application is exposed, and would require no special privileges beyond an unauthenticated or low‑privilege attacker.

Generated by OpenCVE AI on August 21, 2026 at 00:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the PTC security release that addresses the access‑control bypass as soon as it becomes available.
  • Until a patch is available, limit network access to the Windchill servers by using firewall rules, VPNs, or intranet segmentation to restrict exposure to trusted users and systems.
  • Monitor application logs for anomalous authentication attempts or unauthorized data access, and implement stricter audit controls around sensitive risk information.

Generated by OpenCVE AI on August 21, 2026 at 00:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Ptc
Ptc windchill Risk And Reliability Enterprise Edition (formerly Relex)
Vendors & Products Ptc
Ptc windchill Risk And Reliability Enterprise Edition (formerly Relex)

Thu, 20 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.
Title Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition
Weaknesses CWE-306
CWE-620
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/RE:M/U:Red'}


Subscriptions

Ptc Windchill Risk And Reliability Enterprise Edition (formerly Relex)
cve-icon MITRE

Status: PUBLISHED

Assigner: PTC

Published:

Updated: 2026-08-26T14:15:58.962Z

Reserved: 2026-08-20T21:52:32.059Z

Link: CVE-2026-77644

cve-icon Vulnrichment

Updated: 2026-08-21T15:37:56.804Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T22:18:06.357

Modified: 2026-09-09T15:52:04.827

Link: CVE-2026-77644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:08:27Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-620

    Unverified Password Change