CVE-2026-84154 PUBLISHED

Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x

Assigner: 3DS
Reserved: 01.09.2026 Published: 29.09.2026 Updated: 29.09.2026

A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor Dassault Systèmes
Product GEOVIA Geospatial Data Manager
Versions Default: unaffected
  • affected from Release 3DEXPERIENCE R2024x Golden to Release 3DEXPERIENCE R2024x.FP.CFA.2632 (incl.)
  • affected from Release 3DEXPERIENCE R2025x Golden to Release 3DEXPERIENCE R2025x.FP.CFA.2637 (incl.)
  • affected from Release 3DEXPERIENCE R2026x Golden to Release 3DEXPERIENCE R2026x.FP.CFA.2635 (incl.)

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE