CVE-2026-84154: Dassault Systèmes Geovia Geospatial Data Manager
Critical severity, CVSS 9.9. EPSS: 0.4% chance of exploitation in the next 30 days.
A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.
Affected products
- Dassault Systèmes Geovia Geospatial Data Manager: from 3DEXPERIENCE R2024x Golden, up to and including 3DEXPERIENCE R2024x.FP.CFA.2632; from 3DEXPERIENCE R2025x Golden, up to and including 3DEXPERIENCE R2025x.FP.CFA.2637; from 3DEXPERIENCE R2026x Golden, up to and including 3DEXPERIENCE R2026x.FP.CFA.2635
Published 2026-09-29. Last modified 2026-09-30.