CVE Explorer
CVE-2026-9024
A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"DELMIA Service Process Engineer","vendor":"Dassault Systèmes","versions":[{"lessThanOrEqual":"3DEXPERIENCE R2024x FP.CFA.2537","status":"affected","version":"Release 3DEXPERIENCE R2024x Golden","versionType":"custom"},{"lessThanOrEqual":"3DEXPERIENCE R2025x FP.CFA.2541","status":"affected","version":"Release 3DEXPERIENCE R2025x Golden","versionType":"custom"},{"status":"affected","version":"Release 3DEXPERIENCE R2026x Golden"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ad13efeb108280cfad9876c7dda412c658f97da36b13d6296bbfdfd1060a39f6 · sha256:bb98e9f98977c6f9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ad13efeb108280cfad9876c7dda412c658f97da36b13d6296bbfdfd1060a39f6 · sha256:bb98e9f98977c6f9… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ad13efeb108280cfad9876c7dda412c658f97da36b13d6296bbfdfd1060a39f6 · sha256:bb98e9f98977c6f9… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.3ds.com/trust-center/security/security-advisories/cve-2026-9024"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ad13efeb108280cfad9876c7dda412c658f97da36b13d6296bbfdfd1060a39f6 · sha256:bb98e9f98977c6f9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.