CVE-2026-16279
Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x
CVSS Score
9.3
EPSS Score
0.0%
EPSS Percentile
0th
An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.
| CWE | CWE-285 |
| Vendor | dassault systèmes |
| Product | 3dswymer |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for dassault systèmes 3dswymer
Be the first to know when new critical vulnerabilities affecting dassault systèmes 3dswymer are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Dassault Systèmes / 3DSwymer
Release 3DEXPERIENCE R2023x Golden ≤ Release 3DEXPERIENCE R2023x.FP.CFA.2613 Release 3DEXPERIENCE R2024x Golden ≤ Release 3DEXPERIENCE R2024x.FP.CFA.2632 Release 3DEXPERIENCE R2025x Golden ≤ Release 3DEXPERIENCE R2025x.FP.CFA.2628 Release 3DEXPERIENCE R2026x Golden ≤ Release 3DEXPERIENCE R2026x.FP.CFA.2634