# CVE-2026-16279

## Summary

- **CVE ID:** CVE-2026-16279
- **Severity:** CRITICAL
- **CVSS Score:** 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N)
- **CWE:** CWE-285
- **Published:** Aug 27, 2026
- **Last Modified:** Sep 8, 2026

## Description

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

## Affected Products

- Dassault Systèmes — 3DSwymer (Release 3DEXPERIENCE R2023x Golden)
- Dassault Systèmes — 3DSwymer (Release 3DEXPERIENCE R2024x Golden)
- Dassault Systèmes — 3DSwymer (Release 3DEXPERIENCE R2025x Golden)
- Dassault Systèmes — 3DSwymer (Release 3DEXPERIENCE R2026x Golden)

## References

- [CNA](https://www.3ds.com/trust-center/security/security-advisories/cve-2026-16279)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.25%
- **EPSS Percentile:** 17.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._