CVE-2026-16279
largeImproper Authorization in Dassault 3DPassport/3DSwymer Allows User Account Access
CVE-2026-16279 is an improper authorization flaw (CWE-285) in 3DPassport, Dassault Systemes' identity/login component delivered through 3DSwymer, affecting 3DEXPERIENCE releases R2023x through R2026x. The flaw is reachable over the network without prior privileges, but the CVSS vector (UI:R) indicates some form of user interaction is required to trigger it, and the scope-changed score suggests the authorization failure crosses a security boundary. A successful attacker can gain access to some user accounts, with high impact on confidentiality and integrity and no availability impact. Organizations running 3DPassport/3DSwymer within any 3DEXPERIENCE release from R2023x through R2026x are affected. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS estimates only about a 0.3% chance of exploitation in the next 30 days, so no exploitation is currently known.
What to do: Determine which 3DEXPERIENCE release (R2023x through R2026x) your on-premises or cloud tenant runs and whether 3DPassport/3DSwymer is deployed, then apply Dassault Systemes' official fix for this advisory as soon as it is available (no fixed version is listed in the current data). Until patched, restrict network access to 3DPassport login endpoints and review authentication logs for signs of unauthorized account access.
| Dassault Systemes 3DPassport (delivered via 3DSwymer) | Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x (inclusive; no fixed version specified in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.
- Weakness
- CWE-285
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.