Code injection in Dassault Systèmes products - CVE-2026-84154

 

Code injection in Dassault Systèmes products - CVE-2026-84154

Published: September 29, 2026


Vulnerability identifier: #VU152753
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84154
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation in GEOVIA Geospatial Data Manager. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the target system.


Affected software

Geospatial Data Manager
Geospatial Data Engineer
Geospatial Designer
Geospatial Viewer
Geospatial Index
Geospatial Small Index
City Planner for Education

How to mitigate CVE-2026-84154

Install updates from vendor's website.


External References

Related Security Bulletins