CVE-2026-84154: Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x
Published Sep 29, 2026
·Updated
A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.
Affected Software
1 affected component
Dassault Systèmes GEOVIA Geospatial Data Manager>=3DEXPERIENCE R2024x<=3DEXPERIENCE R2026x
Event History
Sep 29, 2026
CVE Published
via MITRE·07:02 AM
Data Sourced
via MITRE·07:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low privileges. Exploitation does not require user interaction and can be performed over the network.
2
What is the potential impact if exploitation succeeds?
An attacker could execute arbitrary code on the server. The reported impact includes high confidentiality, integrity, and availability impact, with scope changed.
3
Which releases should be assessed for exposure?
Assess GEOVIA Geospatial Data Manager deployments from 3DEXPERIENCE R2024x through 3DEXPERIENCE R2026x. The provided information does not identify unaffected releases or a fixed version.