Junglewise Threat Intelligence

CVE-2026-77646: PTC Windchill PDMLink server-side request forgery via deserialization

CVE-2026-77646 · Severity: info · Published 2026-08-20

Technologies: PTC FlexPLM. Vendors: PTC.

Executive brief

PTC Windchill PDMLink is a product lifecycle management system used to manage engineering designs and product data across organizations. A server-side request forgery vulnerability in the deserialization functionality could allow an attacker to make unauthorized network requests from the server, potentially accessing internal systems, exfiltrating sensitive data, or launching attacks against backend infrastructure that would normally be restricted from external access.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in PTC Windchill PDMLink that is triggered through deserialization of untrusted data. The vulnerability allows an attacker to craft malicious serialized input that, when deserialized by the application, causes the server to make arbitrary network requests to internal or external systems. The attack likely requires network access to the application endpoint accepting the untrusted serialized data. Successful exploitation enables information disclosure from internal systems and potential lateral movement within the network. Patch availability status is unknown from the available references.

Affected products

  • PTC Windchill PDMLink
  • PTC FlexPLM

Timeline

  • 2026-08-20: disclosed

References

Related threats