Stored Cross-site Scripting Vulnerability in DELMIA Service Process Engineer
CVE-2026-9024

8.7HIGH

What is CVE-2026-9024?

A Stored Cross-site Scripting (XSS) vulnerability exists in the DELMIA Service Process Engineer application, impacting versions from 3DEXPERIENCE R2024x to R2026x. This vulnerability enables attackers to execute arbitrary scripts within the user's browser session, potentially compromising sensitive user data and accounts. Users are advised to apply security updates promptly to mitigate risks associated with this vulnerability.

Affected Version(s)

DELMIA Service Process Engineer Release 3DEXPERIENCE R2024x Golden <= 3DEXPERIENCE R2024x FP.CFA.2537

DELMIA Service Process Engineer Release 3DEXPERIENCE R2025x Golden <= 3DEXPERIENCE R2025x FP.CFA.2541

DELMIA Service Process Engineer Release 3DEXPERIENCE R2026x Golden

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.