CVE-2026-2101: Dassault Systèmes Enoviavpm Web Access

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary script code in user's browser session.

Affected products

Published 2026-02-16. Last modified 2026-06-17.