Skip to content
eastbaycyber

CVE-2026-84154: GEOVIA Code Injection

CVSS · Critical
9.9
In CISA KEV
No
Published
Sep 29
CVE explainers 10 min read
Security Research Desk Source-checked
Auto-checked against the official CVE record · Human-reviewed after publishing · Updated 2026-09-29
▲ Escalation ViewOne CVE, briefed at three altitudes — skim the Brief, weigh the Impact, or work the Runbook. The way a SOC actually reads it.
CISOBrief · 30-second brief

CVE-2026-84154 is a critical code injection vulnerability affecting Dassault Systèmes GEOVIA Geospatial Data Manager in 3DEXPERIENCE R2024x through R2026x. Organizations should confirm exposure, restrict unnecessary access, and monitor the vendor advisory for fixed-version guidance.

TL;DR - CVE-2026-84154 is a critical code injection vulnerability with a CVSS v3 score of 9.9. - GEOVIA Geospatial Data Manager deployments on 3DEXPERIENCE R2024x through R2026x are affected. - No verified public PoC or confirmed active exploitation was identified; restrict exposure and await confirmed vendor remediation. - The complete CVSS vector, vulnerable builds, fixed version, and workaround were not available in the retrieved record.

Vulnerability at a Glance

Field Details
CVE ID CVE-2026-84154
Vulnerability type Code injection
CVSS score 9.9, CVSS v3
Attack vector Not disclosed in the retrieved NVD summary
Authentication required Not disclosed
Privileges required Not disclosed
Affected product GEOVIA Geospatial Data Manager
Affected releases 3DEXPERIENCE R2024x through R2026x
Patch available Not confirmed
Fixed version Not confirmed
CISA KEV status Not listed as of 2026-09-29

CVE-2026-84154 was published by the National Vulnerability Database on September 29, 2026. The available description says the flaw could allow an attacker to execute arbitrary code on the server. That impact makes the issue operationally significant, even though several technical fields remain unavailable in the initial record.

The NVD summary does not expose the complete CVSS vector, exact build boundaries, vulnerable component, authentication requirements, or deployment prerequisites. Defenders should not infer that the service is unauthenticated, internet-facing, or exploitable remotely without confirmation from the Dassault Systèmes advisory.

Analyst’s Take: The 9.9 score and stated code-execution impact justify urgent exposure checks, but the missing vector and deployment details limit what can be concluded about exploitability. Start with inventory, access restriction, and telemetry rather than assuming a specific attack path.

What Is This Vulnerability?

CVE-2026-84154 is classified as a code injection vulnerability in GEOVIA Geospatial Data Manager, a Dassault Systèmes product within the 3DEXPERIENCE platform. In practical terms, successful exploitation could cause attacker-controlled code or commands to be interpreted and executed by the server-side application.

Depending on the service account and host permissions, the resulting access could expose geospatial data, credentials, application secrets, or connected enterprise systems.

The precise root cause has not been published in the retrieved NVD data. There is no confirmed description of the affected endpoint, input field, parser, API, expression evaluator, or server-side component. Organizations should therefore avoid assuming that a particular request pattern or exploit technique applies. The authoritative technical details should come from the Dassault Systèmes advisory or a subsequent vendor update.

Because code execution is the stated impact, compromise of the application host should be considered possible if suspicious activity is observed. Investigation should include the GEOVIA server, operating system, service-account activity, outbound connections, scheduled tasks, newly created files, and credentials accessible to the application process.

Technical Notes

The available record supports the following confirmed technical statement:

CVE-2026-84154:
A code injection vulnerability affecting GEOVIA Geospatial Data Manager
from 3DEXPERIENCE R2024x through 3DEXPERIENCE R2026x may allow
arbitrary code execution on the server.

No reliable public network signature, vulnerable parameter, exploit payload, or vendor-provided detection rule was identified. Detection teams should not treat generic strings such as ${, ;, or cmd= as validated signatures for this CVE. Those indicators may produce substantial false positives unless correlated with application-specific requests and process execution.

For background on incident handling in mobile and distributed environments, see the Mobile Incident Response Playbook (MIRP).

AnalystImpact · assess the risk

Who Is Affected?

The affected product is Dassault Systèmes GEOVIA Geospatial Data Manager. The NVD record identifies affected 3DEXPERIENCE releases from R2024x through R2026x, inclusive.

The available information does not identify narrower service-pack, hotfix, build, or deployment boundaries. Organizations running any of those release families should treat the installation as potentially affected until Dassault Systèmes provides more precise guidance.

Exposure depends on whether the affected GEOVIA component is installed, enabled, and reachable in the organization’s deployment. The record does not confirm whether exploitation requires authentication, a particular user role, access to an internal network, or a specific 3DEXPERIENCE configuration.

Internet exposure should be considered especially sensitive, but an internal-only deployment still requires remediation because attackers frequently reach enterprise applications through compromised accounts, VPN access, or another breached system.

The following environments require inventory and validation:

  • GEOVIA Geospatial Data Manager on 3DEXPERIENCE R2024x.
  • GEOVIA Geospatial Data Manager on 3DEXPERIENCE R2025x.
  • GEOVIA Geospatial Data Manager on 3DEXPERIENCE R2026x.
  • Replicated, standby, test, development, and disaster-recovery instances using the affected release families.
  • Reverse proxies, API gateways, or integration services that publish access to the component.

No fixed version has been confirmed. Do not assume that R2027x, a later maintenance level, or a general 3DEXPERIENCE update resolves the issue unless the vendor explicitly states that it does.

CVSS Score Breakdown

NVD assigns CVE-2026-84154 a CVSS v3 base score of 9.9, which is in the critical severity range. The score indicates that the combination of exploitability and impact is potentially severe. It should drive expedited asset identification, access restriction, vendor coordination, and incident monitoring.

The retrieved NVD response supplied the score without the CVSS vector string. The individual metric values therefore cannot be stated reliably. The following fields remain unconfirmed:

CVSS component Status
Attack Vector Not disclosed
Attack Complexity Not disclosed
Privileges Required Not disclosed
User Interaction Not disclosed
Scope Not disclosed
Confidentiality Impact Not disclosed
Integrity Impact Not disclosed
Availability Impact Not disclosed

The 9.9 score should not be reverse-engineered into a guessed vector. In particular, the score alone does not prove that exploitation is possible over the public internet or without authentication. Security teams should update their risk assessment when the full vector and vendor technical details become available.

Exploitation Status

CVE-2026-84154 was not listed in the CISA Known Exploited Vulnerabilities catalog at the time of the research check on September 29, 2026. There is therefore no CISA-added date, federal remediation deadline, ransomware campaign designation, or CISA-required action associated with this CVE at that time.

No verified public proof of concept, exploit repository, or confirmed exploitation report was identified in the supplied research. The current assessment is: active exploitation not confirmed, public PoC not confirmed, exploit maturity unknown.

Absence from KEV does not prove that exploitation has not occurred; it means CISA had not included the vulnerability in its catalog when checked.

Organizations should still treat a critical code execution flaw as a high-priority exposure. Attackers may exploit newly disclosed vulnerabilities before public reporting or KEV inclusion, and vendor advisories can contain additional details not yet reflected in NVD.

Monitor endpoint, application, identity, and network telemetry while awaiting remediation instructions. Organizations using endpoint security tooling may also review alerts with Malwarebytes as part of a broader, independently validated detection strategy.

Security teams tracking newly disclosed vulnerabilities can also review the CVE-2026-10187 analysis and the CVE-2026-14365 analysis. These resources should supplement—not replace—the vendor advisory and product-specific remediation instructions.

ResponderRunbook · act now

How to Detect It

The initial public information does not identify a vulnerable endpoint, request parameter, log file format, process name, or exploit payload. There is no validated CVE-specific detection signature that can be responsibly published from the available evidence.

Start by identifying every GEOVIA Geospatial Data Manager instance and collecting its application, reverse-proxy, operating-system, authentication, and process-execution logs.

Look for:

  • Unexpected child processes originating from the GEOVIA or application-server account.
  • New executable files in application and temporary directories.
  • Unusual outbound connections.
  • Requests immediately preceding server-side process creation.
  • Unexpected changes to scheduled tasks, startup items, or service configuration.
  • Access to credentials or secrets by the application process that is inconsistent with normal operations.

These indicators are not proof of CVE-2026-84154 exploitation, but they are appropriate triage signals for a code injection vulnerability.

Technical Notes

A generic Linux audit query for processes launched by an application service account can help identify suspicious execution. Replace geovia with the actual service account after confirming the deployment:

sudo ausearch -m EXECVE --start recent \
  | grep -Ei 'geovia|java|tomcat|wildfly|python|sh|bash|cmd|powershell'

A SIEM detection can begin with a correlation rule similar to the following pseudocode. The process names and account values must be adapted to the installation:

WHEN
  process.parent_user IN ("geovia", "svc-geovia", "tomcat")
  AND process.name IN ("sh", "bash", "cmd.exe", "powershell.exe", "curl", "wget")
  AND process.parent_name IN ("java", "geovia-server", "application-server")
THEN
  alert "Unexpected child process from GEOVIA application service"
  include host, user, parent command line, child command line, and timestamp

Review reverse-proxy logs for requests that precede these events. Do not label a request as a CVE exploit solely because it contains shell metacharacters or template syntax. Correlate the request with process creation, authentication events, file changes, and outbound traffic.

Mitigation and Patching

A fixed version and patch identifier were not confirmed in the retrieved NVD summary. The Dassault Systèmes security advisory is the authoritative source for the remediation version, but its rendered advisory content was not available in the research retrieval.

Administrators should monitor the advisory and contact Dassault Systèmes support for the precise upgrade path.

Until a vendor-confirmed fix is available:

  • Restrict access to GEOVIA Geospatial Data Manager through network controls.
  • Require authenticated administrative access where supported.
  • Remove unnecessary internet exposure.
  • Limit access to approved administration networks.
  • Review and reduce service-account permissions.
  • Increase application, endpoint, identity, and network monitoring.
  • Preserve relevant logs before making disruptive changes.

Do not deploy an unverified workaround that could disrupt the 3DEXPERIENCE platform or bypass required security controls. A password manager such as 1Password may support broader credential hygiene, but it does not remediate this server-side vulnerability.

Technical Notes

There is no confirmed vendor-specific upgrade command or fixed release in the available data. Do not substitute an assumed release such as R2027x.

After Dassault Systèmes publishes a fixed release, use the vendor-supplied installer or platform procedure and record the resulting build number. The following command retrieves the advisory for review, but it does not patch the product:

curl --fail --location --max-time 20 \
  https://www.3ds.com/trust-center/security/security-advisories/cve-2026-84154

As an interim network-control example, a Linux host firewall can block inbound access to a service port from all but an approved administration subnet. Replace the port and subnet only after confirming the deployment and change impact:

sudo firewall-cmd --permanent \
  --add-rich-rule='rule family="ipv4" source address="10.20.0.0/16" port port="443" protocol="tcp" accept'

sudo firewall-cmd --permanent \
  --add-rich-rule='rule family="ipv4" port port="443" protocol="tcp" drop'

sudo firewall-cmd --reload

This is an illustrative containment control, not a Dassault Systèmes workaround. Validate firewall-rule ordering and application dependencies before deployment.

If a host cannot be isolated without affecting production, place the service behind an authenticated reverse proxy, limit source networks, and increase monitoring until the vendor provides a confirmed fix.

After patching:

  1. Verify the exact installed release and build against the vendor advisory.
  2. Restart the affected services according to Dassault Systèmes procedures.
  3. Test core GEOVIA workflows.
  4. Confirm that access controls remain effective.
  5. Review logs for post-patch exploitation attempts.
  6. If compromise indicators are present, preserve logs and disk evidence before making changes.
  7. Rotate credentials available to the application and investigate connected systems.

References

The primary technical source is the Dassault Systèmes security advisory for CVE-2026-84154. Check it for the fixed release, build-specific applicability, CVSS vector, workaround, and product-specific installation instructions:

The NVD record provides the initial vulnerability description, affected release families, publication date, and CVSS v3 score. Because the retrieved record did not include all technical fields, administrators should recheck it for updates:

CISA’s Known Exploited Vulnerabilities catalog was checked for exploitation status. The CVE was not listed at the time of research, but catalog status can change and should not be treated as a substitute for vendor remediation guidance:

This assessment reflects information available on September 29, 2026. The exact CVSS vector, CWE, vulnerable builds, fixed version, workaround, and exploitation evidence should be updated when Dassault Systèmes or NVD publishes additional information.

This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.

Last verified: 2026-09-29

Disclaimer: This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.