CVE-2026-84154 Details
Description
A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.
A code injection vulnerability has been identified in GEOVIA Geospatial Data Manager, affecting versions from 3DEXPERIENCE R2024x to R2026x. This vulnerability could allow an attacker to execute arbitrary code on the server.
Users can refer to the 3DS Support Knowledge Base for remediation information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.3ds.com/trust-center/security/security-advisories/cve-2026-84154 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Dassault Systèmes GEOVIA Geospatial Data Manager | >= 3DEXPERIENCE R2024x, <= 3DEXPERIENCE R2026x |
CPE
Remediation
| |
| Dassault Systèmes GEOVIA Geospatial Data Engineer | All versions |
CPE
Remediation
| |
| Dassault Systèmes GEOVIA Geospatial Designer | All versions |
CPE
Remediation
| |
| Dassault Systèmes GEOVIA Geospatial Viewer | All versions |
CPE
Remediation
| |
| Dassault Systèmes GEOVIA Geospatial Index | All versions |
CPE
Remediation
| |
| Dassault Systèmes GEOVIA Geospatial Small Index | All versions |
CPE
Remediation
| |
| Dassault Systèmes GEOVIA City Planner for Education | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion