Sceawere

Vulnerability Detail

CVE-2026-16279UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

3DPassport Improper Authorization Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
2h ago
Vendor
Dassault Systèmes
Product
3DSwymer
Attack Type
CWE-285 Improper Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-08-27T17:17:14.460Z",
  "pubdate": "2026-08-27T17:17:14.460Z",
  "executiveSummary": "An improper authorization vulnerability has been identified within the 3DPassport component of the 3DSwymer application, part of the 3DEXPERIENCE platform.\nThis flaw allows unauthorized actors to bypass established access control mechanisms, potentially resulting in unauthorized access to sensitive user accounts.\nThe vulnerability affects multiple releases, specifically from 3DEXPERIENCE R2023x through R2026x, posing significant risks to user data confidentiality and account integrity.\nSuccessful exploitation enables an attacker to assume the identity or access the resources of legitimate users without requiring valid authentication credentials.\nThe inherent risk implications include unauthorized data exposure, potential modification of account settings, and unauthorized access to collaborative projects within 3DSwymer.\nExploitation does not necessarily require deep system-level privileges but leverages flaws in the authorization logic handled by 3DPassport to gain unauthorized entry.",
  "technicalDetails": "The vulnerability originates from a critical weakness in the authorization logic within the 3DPassport component of the 3DSwymer application. 3DPassport serves as the centralized identity and access management (IAM) framework for the 3DEXPERIENCE platform, responsible for validating user sessions and enforcing access control policies.\nThe root cause is an improper validation of authorization tokens or a failure to enforce authorization checks during specific request processing sequences. By failing to correctly verify the requesting entity's permissions against the target account, 3DPassport inadvertently grants access to protected resources.\nThe attack flow typically involves an attacker crafting requests to 3DPassport that bypass the intended security checks. Because the authorization check is either omitted or improperly implemented during the request lifecycle, the application processes the request as if it were initiated by an authorized user.\nAffected versions include 3DEXPERIENCE R2023x, R2024x, R2025x, and R2026x. The vulnerability resides within the authentication and authorization handling components of the 3DPassport module, which manages the assertion of user identity across the 3DSwymer environment.\nExploitation does not necessarily require the attacker to have prior authentication; the defect permits the bypass of these requirements entirely. This allows for unauthorized access to target user accounts or sensitive functions typically gated behind successful authentication. The network exposure is broad, as the vulnerability affects the public-facing or internal-facing 3DPassport service endpoint.\nOnce the authorization mechanism is circumvented, the attacker can interact with the 3DSwymer application using the privileges of the victim user. Post-exploitation impact is severe, as it facilitates unauthorized access to private data, collaborative workspaces, and potentially sensitive proprietary information managed within the 3DEXPERIENCE ecosystem.\nThis vulnerability highlights a failure in the 'Secure by Design' principle regarding identity propagation, specifically where the 3DPassport mechanism fails to uphold the principle of least privilege due to logic flaws in token handling or session validation routines."
}
CVE-2026-16279: 3DPassport Improper Authorization Vulnerability (CRITICAL Severity, CVSS: 9.3) - Sceawere