🔐 CVE Alert

CVE-2026-16279

CRITICAL 9.3

Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x

CVSS Score
9.3
EPSS Score
0.0%
EPSS Percentile
0th

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

CWE CWE-285
Vendor dassault systèmes
Product 3dswymer
Published Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for dassault systèmes 3dswymer

Be the first to know when new critical vulnerabilities affecting dassault systèmes 3dswymer are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Dassault Systèmes / 3DSwymer
Release 3DEXPERIENCE R2023x Golden ≤ Release 3DEXPERIENCE R2023x.FP.CFA.2613 Release 3DEXPERIENCE R2024x Golden ≤ Release 3DEXPERIENCE R2024x.FP.CFA.2632 Release 3DEXPERIENCE R2025x Golden ≤ Release 3DEXPERIENCE R2025x.FP.CFA.2628 Release 3DEXPERIENCE R2026x Golden ≤ Release 3DEXPERIENCE R2026x.FP.CFA.2634

References

NVD ↗ CVE.org ↗ EPSS Data ↗
3ds.com: https://www.3ds.com/trust-center/security/security-advisories/cve-2026-16279