CVE-2026-84154

Summary

A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.

Affected Software

VendorProductVersion RangeStatus
Dassault SystèmesGEOVIA Geospatial Data ManagerRelease 3DEXPERIENCE R2024x Golden <= Release 3DEXPERIENCE R2024x.FP.CFA.2632affected
Dassault SystèmesGEOVIA Geospatial Data ManagerRelease 3DEXPERIENCE R2025x Golden <= Release 3DEXPERIENCE R2025x.FP.CFA.2637affected
Dassault SystèmesGEOVIA Geospatial Data ManagerRelease 3DEXPERIENCE R2026x Golden <= Release 3DEXPERIENCE R2026x.FP.CFA.2635affected

Weaknesses

  • CWE-94: CWE-94 Improper Control of Generation of Code ('Code Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References