CVE-2026-16279: Dassault Systèmes 3dswymer

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

Affected products

  • Dassault Systèmes 3dswymer: from 3DEXPERIENCE R2023x Golden, up to and including 3DEXPERIENCE R2023x.FP.CFA.2613; from 3DEXPERIENCE R2024x Golden, up to and including 3DEXPERIENCE R2024x.FP.CFA.2632; from 3DEXPERIENCE R2025x Golden, up to and including 3DEXPERIENCE R2025x.FP.CFA.2628; from 3DEXPERIENCE R2026x Golden, up to and including 3DEXPERIENCE R2026x.FP.CFA.2635

Published 2026-08-27. Last modified 2026-09-08.