CVE-2025-6205: Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

Critical severity, CVSS 9.1. Actively exploited: in CISA KEV since 2025-10-28. EPSS: 73.8% chance of exploitation in the next 30 days.

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

Affected products

  • 3ds DELMIA Apriso: from 2020, before 2025 (fixed in 2025)

Published 2025-08-04. Last modified 2026-06-17.