CVE-2026-2101
Published: Feb 16, 2026
Modified: Feb 17, 2026
CVSS v3.1
8.7
Description
A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary script code in user's browser session.
| Vendor | Product | Versions |
|---|---|---|
Dassault Systèmes | ENOVIAvpm Web Access | affected ENOVIAvpm V1R16 Golden - <= ENOVIAvpm V1R16 SP6affected ENOVIAvpm V1R17 Golden - <= ENOVIAvpm V1R17 SP5affected ENOVIAvpm V1R18 Golden - <= ENOVIAvpm V1R18 SP3affected ENOVIAvpm V1R19 Golden - <= ENOVIAvpm V1R19 SP1 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now