Code Injection Vulnerability in GEOVIA Geospatial Data Manager by Dassault Systèmes
CVE-2026-84154

9.9CRITICAL

Key Information:

Vendor
CVE Published:
29 September 2026

What is CVE-2026-84154?

A code injection vulnerability exists in GEOVIA Geospatial Data Manager, spanning from Release 3DEXPERIENCE R2024x to R2026x, potentially allowing attackers to execute arbitrary code on the server. This vulnerability could lead to significant security risks if exploited, as it enables unauthorized access to system functionality and sensitive data. Organizations utilizing these releases should take immediate action to assess their exposure and implement necessary security measures.

Affected Version(s)

GEOVIA Geospatial Data Manager Release 3DEXPERIENCE R2024x Golden

GEOVIA Geospatial Data Manager Release 3DEXPERIENCE R2025x Golden

GEOVIA Geospatial Data Manager Release 3DEXPERIENCE R2026x Golden

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.