Executive brief
3DPassport is Dassault Systèmes' identity and access management system used in the 3DSwymer collaboration platform. An authorization flaw allows attackers to gain unauthorized access to user accounts without requiring proper authentication. This could lead to account takeover, unauthorized data access, and compromise of collaborative design and engineering projects stored in the platform.
Technical details
The vulnerability is an improper authorization flaw in the 3DPassport authentication component of 3DSwymer. Attackers can bypass authorization controls to gain access to user accounts across affected releases (3DEXPERIENCE R2023x through R2026x). The attack requires network access to the 3DSwymer service but no prior authentication. Successful exploitation allows attackers to impersonate legitimate users and access sensitive project data, design files, and collaborative content. Patches are expected to be available from Dassault Systèmes for all affected versions.
Affected products
- Dassault Systèmes 3DSwymer 3DEXPERIENCE R2023x through R2026x
Timeline
- 2026-08-27: disclosed
- 2026-09-08: advisory