{"id":"CVE-2026-84154","published":"2026-09-29T08:17:21.297","lastModified":"2026-09-29T17:17:10.507","description":"A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.","cvssScore":9.9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://www.3ds.com/trust-center/security/security-advisories/cve-2026-84154","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"A Code Injection vulnerability in GEOVIA Geospatial Data Manager allows attackers to execute arbitrary code on the server, posing a critical risk.","exploitability":"Exploitation is relatively easy given the attacker can inject code, but requires access to the affected software version.","blast_radius":"If exploited, this vulnerability could lead to complete server compromise, including data theft and loss of control over the system.","remediation":"Upgrade to Release 3DEXPERIENCE R2026x or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","code-injection","server-compromise","critical"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T08:50:25.199Z"}}