Sceawere
Vulnerability Detail
CVE-2026-16279UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
3DPassport Improper Authorization Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 2h ago
- Vendor
- Dassault Systèmes
- Product
- 3DSwymer
- Attack Type
- CWE-285 Improper Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-08-27T17:17:14.460Z",
"pubdate": "2026-08-27T17:17:14.460Z",
"executiveSummary": "An improper authorization vulnerability has been identified within the 3DPassport component of the 3DSwymer application, part of the 3DEXPERIENCE platform.\nThis flaw allows unauthorized actors to bypass established access control mechanisms, potentially resulting in unauthorized access to sensitive user accounts.\nThe vulnerability affects multiple releases, specifically from 3DEXPERIENCE R2023x through R2026x, posing significant risks to user data confidentiality and account integrity.\nSuccessful exploitation enables an attacker to assume the identity or access the resources of legitimate users without requiring valid authentication credentials.\nThe inherent risk implications include unauthorized data exposure, potential modification of account settings, and unauthorized access to collaborative projects within 3DSwymer.\nExploitation does not necessarily require deep system-level privileges but leverages flaws in the authorization logic handled by 3DPassport to gain unauthorized entry.",
"technicalDetails": "The vulnerability originates from a critical weakness in the authorization logic within the 3DPassport component of the 3DSwymer application. 3DPassport serves as the centralized identity and access management (IAM) framework for the 3DEXPERIENCE platform, responsible for validating user sessions and enforcing access control policies.\nThe root cause is an improper validation of authorization tokens or a failure to enforce authorization checks during specific request processing sequences. By failing to correctly verify the requesting entity's permissions against the target account, 3DPassport inadvertently grants access to protected resources.\nThe attack flow typically involves an attacker crafting requests to 3DPassport that bypass the intended security checks. Because the authorization check is either omitted or improperly implemented during the request lifecycle, the application processes the request as if it were initiated by an authorized user.\nAffected versions include 3DEXPERIENCE R2023x, R2024x, R2025x, and R2026x. The vulnerability resides within the authentication and authorization handling components of the 3DPassport module, which manages the assertion of user identity across the 3DSwymer environment.\nExploitation does not necessarily require the attacker to have prior authentication; the defect permits the bypass of these requirements entirely. This allows for unauthorized access to target user accounts or sensitive functions typically gated behind successful authentication. The network exposure is broad, as the vulnerability affects the public-facing or internal-facing 3DPassport service endpoint.\nOnce the authorization mechanism is circumvented, the attacker can interact with the 3DSwymer application using the privileges of the victim user. Post-exploitation impact is severe, as it facilitates unauthorized access to private data, collaborative workspaces, and potentially sensitive proprietary information managed within the 3DEXPERIENCE ecosystem.\nThis vulnerability highlights a failure in the 'Secure by Design' principle regarding identity propagation, specifically where the 3DPassport mechanism fails to uphold the principle of least privilege due to logic flaws in token handling or session validation routines."
}