CVE-2025-6205: Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability
Critical severity, CVSS 9.1. Actively exploited: in CISA KEV since 2025-10-28. EPSS: 73.8% chance of exploitation in the next 30 days.
A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.
Affected products
- 3ds DELMIA Apriso: from 2020, before 2025 (fixed in 2025)
Published 2025-08-04. Last modified 2026-06-17.