Sceawere

Vulnerability Detail

CVE-2026-84154UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GEOVIA Geospatial Data Manager Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
17h ago
Vendor
Dassault Systèmes
Product
GEOVIA Geospatial Data Manager
Attack Type
CWE-94 Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-09-29T08:17:21.297Z",
  "pubdate": "2026-09-29T08:17:21.297Z",
  "executiveSummary": "A critical Code Injection vulnerability has been identified within the GEOVIA Geospatial Data Manager, affecting software releases spanning from 3DEXPERIENCE R2024x through 3DEXPERIENCE R2026x.\nThis vulnerability allows an unauthenticated or authenticated attacker, depending on the implementation context, to inject and execute arbitrary code directly on the host server.\nThe core issue stems from improper sanitization of input data processed by the application, which facilitates the execution of malicious commands.\nSuccessful exploitation results in full system compromise, granting the attacker the ability to execute OS-level commands with the privileges of the application service.\nThe risk is categorized as critical, as it bypasses standard security controls and provides a vector for lateral movement, data exfiltration, or complete system takeover.\nOrganizations using the specified versions of the 3DEXPERIENCE platform must treat this vulnerability with the highest priority, focusing on immediate risk assessment and implementation of compensating controls until vendor-supplied patches are applied.",
  "technicalDetails": "The Code Injection vulnerability in GEOVIA Geospatial Data Manager arises from the unsafe handling of user-supplied input strings before they are interpreted or executed by the server-side engine.\nIn the context of the 3DEXPERIENCE R2024x through R2026x releases, the application fails to adequately validate or encode data inputs processed by specific internal components responsible for data management and geospatial data ingestion.\nWhen an attacker submits a crafted payload containing malicious code, the underlying server-side environment interprets the input as executable instructions rather than passive data. This flaw indicates a lack of proper input validation, output encoding, or the use of dangerous functions that execute system-level commands, such as eval(), system(), or equivalent OS command invocation APIs.\nThe attack flow typically follows a structured sequence: First, the attacker identifies an entry point, such as a file upload, API request, or configuration field, where user-defined input is accepted. Second, the attacker crafts a payload designed to escape the application's input boundary and trigger the injection point. Third, the payload is transmitted to the server, where the vulnerable component processes the string without sanitization. Fourth, the application engine executes the injected payload in the context of the application's service account.\nThe post-exploitation impact is severe. Since the code executes within the server process, an attacker gains the ability to interact with the underlying operating system. This allows for the installation of persistent backdoors, the execution of arbitrary scripts, unauthorized access to sensitive geospatial datasets, and the potential to move laterally within the network infrastructure.\nBecause the vulnerability persists across the R2024x to R2026x range, it suggests a systemic issue within the integration of third-party or proprietary modules used by the Geospatial Data Manager. The lack of robust security constraints allows for bypasses that would otherwise be blocked by modern security frameworks. Remediation requires identifying the specific execution contexts and strictly enforcing input whitelisting and privilege-restricted execution environments to isolate the application from the underlying OS kernel."
}
CVE-2026-84154: GEOVIA Geospatial Data Manager Injection (CRITICAL Severity, CVSS: 9.9) | Sceawere