{"id":"CVE-2026-84154","title":"A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.","summary":"A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-94"],"vendor":"Dassault Systèmes","product":"GEOVIA Geospatial Data Manager","affected":["geovia_geospatial_data_manager >= Release 3DEXPERIENCE R2024x Golden <= Release 3DEXPERIENCE R2024x.FP.CFA.2632","geovia_geospatial_data_manager >= Release 3DEXPERIENCE R2025x Golden <= Release 3DEXPERIENCE R2025x.FP.CFA.2637","geovia_geospatial_data_manager >= Release 3DEXPERIENCE R2026x Golden <= Release 3DEXPERIENCE R2026x.FP.CFA.2635"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T08:17:21.297","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84154","references":[{"url":"https://www.3ds.com/trust-center/security/security-advisories/cve-2026-84154","label":"3DS.Information-Security@3ds.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T08:30:07.396Z","slug":"CVE-2026-84154","body":"## Overview\n\nA Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":54.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}