Executive brief
DELMIA Apriso, a manufacturing operations management platform used to manage global production and supply chains, contains a critical security flaw. This vulnerability allows an unauthorized person to bypass security checks and gain administrative control over the server. An attacker could use this access to disrupt manufacturing operations, steal sensitive production data, or compromise the integrity of the supply chain.
Technical details
An improper authentication vulnerability (CWE-287) exists in Dassault Systèmes DELMIA Apriso. The flaw allows a remote, unauthenticated attacker to bypass authentication mechanisms and gain high-privileged access to the server. The vulnerability is exploitable over the network with low complexity and requires no user interaction. Affected versions range from Release 2020 Golden through Release 2026 SP1. Users are advised to consult the Dassault Systèmes Trust Center for specific remediation and patching information.
Affected products
- Dassault Systèmes DELMIA Apriso Release 2020 through Release 2026
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory