Dassault SystèmesCVE-2026-16279
Dassault Systèmes 3DSwymer: improper authorization
Critical9.3CVE-2026-16279 · Published Aug 27, 2026 · updated Sep 8, 2026
An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| 3DSwymer Product | >= Release 3DEXPERIENCE R2023x Golden, <= Release 3DEXPERIENCE R2023x.FP.CFA.2613 | No fix yet |
| >= Release 3DEXPERIENCE R2024x Golden, <= Release 3DEXPERIENCE R2024x.FP.CFA.2632 | No fix yet | |
| >= Release 3DEXPERIENCE R2025x Golden, <= Release 3DEXPERIENCE R2025x.FP.CFA.2628 | No fix yet | |
| >= Release 3DEXPERIENCE R2026x Golden, <= Release 3DEXPERIENCE R2026x.FP.CFA.2635 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-285
More Dassault Systèmes advisories
All Dassault Systèmes| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 21 | Dassault Systèmes Tuleap Enterprise Edition: command injection | High8.8 | No fix yet |
| Aug 25 | Dassault Systèmes Tuleap Enterprise: attacker could gain access to user... | High7.7 | No fix yet |
| Aug 11 | Dassault Systèmes SIMULIA Execution Engine: unsafe deserialization | Critical10.0 | No fix yet |
| Jul 28 | Dassault Systèmes Station Launcher App: unsafe deserialization | Critical10.0 | No fix yet |
| Jul 13 | Dassault Systèmes Tuleap Enterprise Edition: insecure direct object reference | High7.5 | No fix yet |
| Jul 8 | Dassault Systèmes DELMIA Apriso: improper authentication | Critical9.8 | No fix yet |