← Back to overview

An Improper Authorization vulnerability has been identified in 3DPassport, a component of 3DSwymer by Dassault Systèmes. The vulnerability affects releases from 3DEXPERIENCE R2023x through R2026x. If exploited, an attacker could gain unauthorized access to certain user accounts. The flaw is classified as an Improper Authorization issue, meaning access controls are insufficiently enforced. This could allow privilege escalation or account takeover for some users. The vulnerability is tracked as CVE-2026-16279 and has been assigned a high criticality rating. Dassault Systèmes has published a security advisory through their Trust Center. Users running affected versions are advised to review the advisory and apply any available patches or mitigations promptly.

Affected products

  • 3DEXPERIENCE R2023x
  • 3DEXPERIENCE R2024x
  • 3DEXPERIENCE R2025x
  • 3DEXPERIENCE R2026x
  • 3DPassport
  • 3DSwymer

Related CVE's

  • CVE-2026-16279

Categories

  • Enterprise Applications
  • Identity & Access