Executive brief
The Bentley Systems iTwin Platform, a cloud service used for infrastructure digital twins, inadvertently exposed a sensitive Cesium ion access token within the source code of its web pages. An unauthorized person could have used this token to view or delete digital assets and data stored within the platform. Bentley Systems has since removed the token and revoked its access, neutralizing the threat to customer operations and data.
Technical details
A sensitive information disclosure vulnerability (CWE-540) existed in the Bentley Systems iTwin Platform where a Cesium ion access token was embedded in the HTML source code of certain web pages. This token provided unauthenticated network-based attackers with the ability to interact with the Cesium ion REST API. Depending on the token's scopes, an attacker could enumerate metadata or delete assets associated with the account. The vulnerability was remediated on 2026-03-27 by removing the token from web pages and revoking its validity.
Affected products
- Bentley Systems iTwin Platform Versions prior to 2026-03-27
Timeline
- 2026-03-27: patched: Token removed from web pages and access revoked.
- 2026-04-02: disclosed: Initial publication of CVE-2026-35383.