Description
An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.
Published: 2026-07-08
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Authentication flaw that allows an attacker to bypass the standard login process for DELMIA Apriso, giving them privileged access to the server. The weakness is categorized as CWE-287.

Affected Systems

Dassault Systèmes DELMIA Apriso releases from 2020 through 2026 are affected. Any deployment of these releases without the vendor patch is vulnerable.

Risk and Exploitability

The CVSS score of 9.8 reflects critical severity. The EPSS score of < 1% shows a very low probability of exploitation, though exploitation remains possible. The vulnerability is not listed in CISA KEV, indicating no known publicly reported exploits. Based on the description, the attack vector involves interfacing with the authentication mechanism of the Apriso server, and the attacker requires network access to the service; no additional prerequisites are noted.

Generated by OpenCVE AI on July 29, 2026 at 14:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Dassault Systèmes security patch for DELMIA Apriso
  • Restrict network access to the Apriso server to trusted IP ranges with firewall controls
  • Monitor authentication logs for suspicious attempts and investigate promptly

Generated by OpenCVE AI on July 29, 2026 at 14:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Dassault Systèmes
Dassault Systèmes delmia Apriso
Vendors & Products Dassault Systèmes
Dassault Systèmes delmia Apriso

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.
Title Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dassault Systèmes Delmia Apriso
cve-icon MITRE

Status: PUBLISHED

Assigner: 3DS

Published:

Updated: 2026-07-08T13:46:26.318Z

Reserved: 2026-05-27T11:13:55.994Z

Link: CVE-2026-9695

cve-icon Vulnrichment

Updated: 2026-07-08T13:46:20.528Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses