CVE-2026-77646

Summary

A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

Affected Software

VendorProductVersion RangeStatus
PTCWindchill PDMLink11.0 M030affected
PTCWindchill PDMLink11.1 M020affected
PTCWindchill PDMLink11.2.1.0affected
PTCWindchill PDMLink12.0.2.0affected
PTCWindchill PDMLink12.1.2.0affected
PTCWindchill PDMLink13.0.2.0affected
PTCWindchill PDMLink13.1.0.0affected
PTCWindchill PDMLink13.1.1.0affected
PTCWindchill PDMLink13.1.2.0affected
PTCWindchill PDMLink13.1.3.0affected
PTCFlexPLM11.0 M030affected
PTCFlexPLM11.1 M020affected
PTCFlexPLM11.2.1.0affected
PTCFlexPLM12.0.0.0affected
PTCFlexPLM12.0.2.0affected
PTCFlexPLM12.0.3.0affected
PTCFlexPLM12.1.2.0affected
PTCFlexPLM12.1.3.0affected
PTCFlexPLM13.0.2.0affected
PTCFlexPLM13.0.3.0affected

Weaknesses

  • CWE-502: CWE-502 Deserialization of untrusted data
  • CWE-918: CWE-918 Server-Side request forgery (SSRF)

References