Description
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
Published: 2026-08-20
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Server‑Side Request Forgery vulnerability exists in PTC Windchill PDMLink and PTC FlexPLM that can be triggered by deserializing untrusted data. The flaw allows an attacker to craft a payload that forces the application to perform HTTP requests to arbitrary hosts, potentially exposing internal resources and sensitive services to unauthorized users.

Affected Systems

The affected products are PTC FlexPLM and PTC Windchill PDMLink. No specific version information is provided in the advisory.

Risk and Exploitability

The CVSS score of 7.7 classifies the vulnerability as high severity. The EPSS score is not available, so the current exploitation probability is unclear; the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is most likely via sending a maliciously crafted serialized object to the application, which is then processed and results in outbound requests to internal or external destinations.

Generated by OpenCVE AI on August 21, 2026 at 00:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update for Windchill PDMLink and FlexPLM as released by PTC.
  • Restrict the outbound traffic from the Windchill server to only approved destinations using firewall rules or network segmentation.
  • If feasible, disable or sanitize any deserialization mechanisms that accept untrusted input.

Generated by OpenCVE AI on August 21, 2026 at 00:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Ptc
Ptc flexplm
Ptc windchill Pdmlink
Vendors & Products Ptc
Ptc flexplm
Ptc windchill Pdmlink

Thu, 20 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
Title Server Side Request Forgery (SSRF) vulnerability reported in Windchill
Weaknesses CWE-502
CWE-918
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/R:U/V:D/RE:M/U:Red'}


Subscriptions

Ptc Flexplm Windchill Pdmlink
cve-icon MITRE

Status: PUBLISHED

Assigner: PTC

Published:

Updated: 2026-08-21T20:08:38.230Z

Reserved: 2026-08-20T22:07:22.899Z

Link: CVE-2026-77646

cve-icon Vulnrichment

Updated: 2026-08-21T20:06:26.715Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T22:18:06.657

Modified: 2026-09-09T15:52:04.827

Link: CVE-2026-77646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T01:00:04Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data

  • CWE-918

    Server-Side Request Forgery (SSRF)