Skip to content
PTCCVE-2026-77644

PTC Windchill Risk and: improper access control

Critical9.3CVE-2026-77644 · Published Aug 20, 2026 · updated Sep 9, 2026

A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.

PTC advisory

Affected versions

PackageAffectedFixed in
Windchill Risk and Reliability Enterprise Edition (Formerly Relex)
Product
>= 11.1, <= 13.1No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Red
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-306, CWE-620

More PTC advisories

All PTC
Advisory
PTC Windchill: remote code execution
Critical9.2Aug 20
PTC Windchill PDMLink: server-side request forgery
High7.7Aug 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.