CVE-2026-35383
Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated attacker could use this token to enumerate or delete certain assets. As of 2026-03-27, the token is no longer present in the web pages and cannot be used to enumerate or delete assets.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.28%
- CWE
- CWE-540
- Published
- 2026-04-02
- Last modified
- 2026-04-14
Affected products
- Bentley Systems iTwin Platform
- Bentley Systems iTwin Platform
Weakness type
Related vulnerabilities
- CVE-2026-16581 — Inclusion of sensitive information in source code in igloohome Smart Lock Mobile Application
- CVE-2026-45728 — Algernon: Single-file mode unconditionally enables debug mode
- CVE-2026-4155 — ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability
- CVE-2026-22275 — Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0,...
- CVE-2025-36299 — IBM Planning Analytics Information Disclosure
- CVE-2024-38327 — IBM Analytics Content Hub information disclosure
- CVE-2025-49182 — Credential disclosure
- CVE-2025-0923 — IBM Cognos Analytics information disclosure