Junglewise Threat Intelligence

CVE-2026-9024: Dassault Systèmes DELMIA Service Process Engineer stored XSS in Process Experience Studio

CVE-2026-9024 · Severity: high · CVSS 8.7 · Published 2026-06-01

Vendors: Dassault SystèMes.

Executive brief

A security vulnerability exists in Dassault Systèmes DELMIA Service Process Engineer, a software suite used for manufacturing and service process planning. An attacker could inject malicious scripts into the application that execute when other users view specific content. This could lead to the unauthorized access of sensitive user data, session hijacking, or the performance of actions on behalf of legitimate users.

Technical details

A Stored Cross-site Scripting (XSS) vulnerability exists in the Process Experience Studio component of Dassault Systèmes DELMIA Service Process Engineer (3DEXPERIENCE R2024x through R2026x). The flaw is caused by improper neutralization of user-supplied input (CWE-79) before it is stored and subsequently displayed to other users. An authenticated attacker with low privileges can inject malicious JavaScript into the application. When a victim views the affected page, the script executes within the context of their browser session, potentially allowing the attacker to steal session tokens or modify page content. The vulnerability has a CVSS score of 8.7, reflecting a high impact on confidentiality and integrity due to the 'Scope Changed' (S:C) nature of the exploit.

Affected products

  • Dassault Systèmes DELMIA Service Process Engineer (Process Experience Studio) 3DEXPERIENCE R2024x through 3DEXPERIENCE R2026x

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory

References