CVE-2026-9024

Dassault Systèmes · DELMIA Service Process Engineer

A stored Cross-Site Scripting (XSS) vulnerability in Process Experience Studio within DELMIA Service Process Engineer allows authenticated, low-privilege users to execute arbitrary scripts in other users' sessions.

Executive summary

A stored XSS vulnerability in DELMIA Service Process Engineer allows low-privileged users to execute malicious scripts, potentially leading to unauthorized session access.

Vulnerability

This is a stored Cross-Site Scripting (XSS) vulnerability within the Process Experience Studio component. An authenticated user with low-level privileges can inject malicious scripts, which are then stored and executed in the browser sessions of other, potentially higher-privileged, users.

Business impact

With a CVSS score of 8.7, this vulnerability poses a significant risk to the confidentiality and integrity of user sessions. Successful exploitation could lead to session hijacking, unauthorized data access, or the performance of actions on behalf of the victim user, potentially compromising sensitive design and process data.

Remediation

Immediate Action: Apply the security updates provided by Dassault Systèmes as detailed in their official security advisory.

Proactive Monitoring: Monitor application logs for suspicious script injections and review user activity for potential session hijacking attempts.

Compensating Controls: Ensure that appropriate Content Security Policy (CSP) headers are implemented to restrict the execution of unauthorized scripts within the browser.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations deploying DELMIA Service Process Engineer should prioritize applying the vendor-provided updates. Additionally, administrators should educate users on the risks of interacting with untrusted content and enforce strict access controls to limit the impact of potential XSS attacks.