CVE-2026-9024

HIGH

DELMIA Service Process Engineer R2024x-R2026x - Stored Cross-Site Scripting

Title source: manual
STIX 2.1

Description

A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session.

Scores

CVSS v3 8.7
EPSS 0.0020
EPSS Percentile 9.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (3)
Dassault Systèmes/DELMIA Service Process Engineer Release 3DEXPERIENCE R2024x Golden - 3DEXPERIENCE R2024x FP.CFA.2537
Dassault Systèmes/DELMIA Service Process Engineer Release 3DEXPERIENCE R2025x Golden - 3DEXPERIENCE R2025x FP.CFA.2541
Dassault Systèmes/DELMIA Service Process Engineer Release 3DEXPERIENCE R2026x Golden
Published Jun 01, 2026
Tracked Since Jun 01, 2026