Skip to content
PTCCVE-2026-77646

PTC Windchill PDMLink: server-side request forgery

High7.7CVE-2026-77646 · Published Aug 20, 2026 · updated Sep 9, 2026

A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

PTC advisory

Affected versions

PackageAffectedFixed in
FlexPLM
Product
<= 11.0 M030No fix yet
<= 11.1 M020No fix yet
<= 11.2.1.0No fix yet
<= 12.0.0.0No fix yet
Windchill PDMLink
Product
<= 11.0 M030No fix yet
<= 11.1 M020No fix yet
<= 11.2.1.0No fix yet
<= 12.0.2.0No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Red
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-502, CWE-918

More PTC advisories

All PTC
Advisory
PTC Windchill Risk and: improper access control
Critical9.3Aug 20
PTC Windchill: remote code execution
Critical9.2Aug 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.