CVE Explorer
CVE-2026-9695
An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"DELMIA Apriso","vendor":"Dassault Systèmes","versions":[{"lessThanOrEqual":"Release 2020 SP4","status":"affected","version":"Release 2020 Golden","versionType":"custom"},{"lessThanOrEqual":"Release 2021 SP3","status":"affected","version":"Release 2021 Golden","versionType":"custom"},{"lessThanOrEqual":"Release 2022 SP4","status":"affected","version":"Release 2022 Golden","versionType":"custom"},{"lessThanOrEqual":"Release 2023 SP3","status":"affected","version":"Release 2023 Golden","versionType":"custom"},{"lessThanOrEqual":"Release 2024 SP2","status":…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5d2b011977a1890348d91fb91e2a9560f5d94343f0f05f7fb9839e6d440e17d0 · sha256:7810ab3a7c85d872… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5d2b011977a1890348d91fb91e2a9560f5d94343f0f05f7fb9839e6d440e17d0 · sha256:7810ab3a7c85d872… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-287","description":"CWE-287 Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5d2b011977a1890348d91fb91e2a9560f5d94343f0f05f7fb9839e6d440e17d0 · sha256:7810ab3a7c85d872… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.3ds.com/trust-center/security/security-advisories/cve-2026-9695"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5d2b011977a1890348d91fb91e2a9560f5d94343f0f05f7fb9839e6d440e17d0 · sha256:7810ab3a7c85d872… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.