---
id: CVE-2026-16279
title: >-
  An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from
  Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an
  attacker to gain access to some user accounts.
summary: >-
  An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from
  Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an
  attacker to gain access to some user accounts.
severity: critical
cvss: 9.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-285
vendor: Dassault Systèmes
product: 3DSwymer
affected:
  - >-
    3DSwymer >= Release 3DEXPERIENCE R2023x Golden <= Release 3DEXPERIENCE
    R2023x.FP.CFA.2613
  - >-
    3DSwymer >= Release 3DEXPERIENCE R2024x Golden <= Release 3DEXPERIENCE
    R2024x.FP.CFA.2632
  - >-
    3DSwymer >= Release 3DEXPERIENCE R2025x Golden <= Release 3DEXPERIENCE
    R2025x.FP.CFA.2628
  - >-
    3DSwymer >= Release 3DEXPERIENCE R2026x Golden <= Release 3DEXPERIENCE
    R2026x.FP.CFA.2635
published: '2026-08-27'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T06:17:19.503'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16279'
references:
  - url: >-
      https://www.3ds.com/trust-center/security/security-advisories/cve-2026-16279
    label: 3DS.Information-Security@3ds.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-27T19:38:06.678487Z'
epss: 0.00254
epssPercentile: 0.15092
ingestedAt: '2026-09-08T15:33:26.955Z'
---

## Overview

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
