ZeroHour

CVE-2026-16279

large

Improper Authorization in Dassault 3DPassport/3DSwymer Allows User Account Access

CVSS 3.1
9.3 critical
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-16279 is an improper authorization flaw (CWE-285) in 3DPassport, Dassault Systemes' identity/login component delivered through 3DSwymer, affecting 3DEXPERIENCE releases R2023x through R2026x. The flaw is reachable over the network without prior privileges, but the CVSS vector (UI:R) indicates some form of user interaction is required to trigger it, and the scope-changed score suggests the authorization failure crosses a security boundary. A successful attacker can gain access to some user accounts, with high impact on confidentiality and integrity and no availability impact. Organizations running 3DPassport/3DSwymer within any 3DEXPERIENCE release from R2023x through R2026x are affected. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS estimates only about a 0.3% chance of exploitation in the next 30 days, so no exploitation is currently known.

What to do: Determine which 3DEXPERIENCE release (R2023x through R2026x) your on-premises or cloud tenant runs and whether 3DPassport/3DSwymer is deployed, then apply Dassault Systemes' official fix for this advisory as soon as it is available (no fixed version is listed in the current data). Until patched, restrict network access to 3DPassport login endpoints and review authentication logs for signs of unauthorized account access.

Affected
Dassault Systemes 3DPassport (delivered via 3DSwymer)Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x (inclusive; no fixed version specified in available data)
Estimated exposure
largeplausibly on the order of 100,000+ named users across thousands of enterprise 3DEXPERIENCE deployments (estimate; no public install counts available) — Estimated from deployment patterns rather than published counts: 3DEXPERIENCE is deployed primarily at large manufacturing, aerospace and industrial enterprises, and the affected range spans four consecutive annual releases including the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.