Improper Authorization Vulnerability in 3DPassport from 3DSwymer
CVE-2026-16279

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-16279?

An improper authorization vulnerability in 3DPassport within 3DSwymer could potentially enable an attacker to gain unauthorized access to user accounts. This issue affects specific releases of the 3DEXPERIENCE platform, allowing unauthorized individuals to exploit user credentials and manipulate sensitive information.

Affected Version(s)

3DSwymer Release 3DEXPERIENCE R2023x Golden

3DSwymer Release 3DEXPERIENCE R2024x Golden

3DSwymer Release 3DEXPERIENCE R2025x Golden

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.