Code injection in Dassault Systèmes products - CVE-2026-84154
Published: September 29, 2026
Vulnerability identifier: #VU152753
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84154
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in GEOVIA Geospatial Data Manager. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the target system.
Affected software
Geospatial Data Manager
Geospatial Data Engineer
Geospatial Designer
Geospatial Viewer
Geospatial Index
Geospatial Small Index
City Planner for Education
Geospatial Data Engineer
Geospatial Designer
Geospatial Viewer
Geospatial Index
Geospatial Small Index
City Planner for Education
How to mitigate CVE-2026-84154
Install updates from vendor's website.