CVE-2026-84154
Received Received - Intake

Code Injection in GEOVIA Geospatial Data Manager

Vulnerability report for CVE-2026-84154, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Dassault Systèmes

Description

A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
dassault_systèmes geovia_geospatial_data_manager From R2024x (inc) to R2026x (inc)
dassault_systèmes geospatial_data_engineer From R2024x (inc) to R2026x (inc)
dassault_systèmes geospatial_designer From R2024x (inc) to R2026x (inc)
dassault_systèmes geospatial_viewer From R2024x (inc) to R2026x (inc)
dassault_systèmes geospatial_index From R2024x (inc) to R2026x (inc)
dassault_systèmes geospatial_small_index From R2024x (inc) to R2026x (inc)
dassault_systèmes city_planner_for_education From R2024x (inc) to R2026x (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-84154 is a critical Code Injection vulnerability in Dassault Systèmes' GEOVIA Geospatial Data Manager software. It affects versions from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x. An attacker can exploit this flaw to inject and execute arbitrary code on the server.

Detection Guidance

Detection of CVE-2026-84154 requires checking for vulnerable versions of GEOVIA Geospatial Data Manager. Inspect installed software versions and compare them against the affected releases (3DEXPERIENCE R2024x through R2026x). Review server logs for unusual code execution patterns or unauthorized commands.

Impact Analysis

This vulnerability allows attackers to execute arbitrary code on the server, potentially leading to unauthorized access, data theft, system compromise, or disruption of services. It may also enable lateral movement within a network if the server is connected to other systems.

Compliance Impact

This vulnerability could lead to data breaches, which may violate GDPR, HIPAA, or other regulations requiring protection of sensitive data. Non-compliance risks include legal penalties, fines, and reputational damage due to unauthorized access or data exposure.

Mitigation Strategies

Apply remediation measures provided by Dassault Systèmes immediately. Update GEOVIA Geospatial Data Manager to the latest patched version. Restrict network access to the affected software and monitor for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84154. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart