


Perceptive Security
SOC/SIEM Consultancy

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an att…
Published:
27 augustus 2026 om 00:00:00
Alert date:
27 augustus 2026 om 20:17:27
Source:
nvd.nist.gov
Identity & Access, Enterprise Applications
An Improper Authorization vulnerability has been identified in 3DPassport, a component of 3DSwymer by Dassault Systèmes. The vulnerability affects releases from 3DEXPERIENCE R2023x through R2026x. If exploited, an attacker could gain unauthorized access to certain user accounts. The flaw is classified as an Improper Authorization issue, meaning access controls are insufficiently enforced. This could allow privilege escalation or account takeover for some users. The vulnerability is tracked as CVE-2026-16279 and has been assigned a high criticality rating. Dassault Systèmes has published a security advisory through their Trust Center. Users running affected versions are advised to review the advisory and apply any available patches or mitigations promptly.
Technical details
Mitigation steps:
Affected products:
3DPassport
3DSwymer
3DEXPERIENCE R2023x
3DEXPERIENCE R2024x
3DEXPERIENCE R2025x
3DEXPERIENCE R2026x
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-16279
https://www.3ds.com/trust-center/security/security-advisories/cve-2026-16279
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
