CVE-2026-9695
Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026
Description
An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.
In plain language
AI Worth attentionCVE-2026-9695 is an authentication bypass that could let an attacker take over a DELMIA Apriso server over the network, and because there’s no confirmed fixed version yet, small businesses running DELMIA Apriso should take action now to assess exposure.
CVE-2026-9695 is an Improper Authentication (CWE-287) weakness in DELMIA Apriso (Release 2020 through Release 2026) where an attacker can bypass authentication and obtain privileged server access via network access (no authentication or user interaction required).
What to do now
- Check whether your business uses DELMIA Apriso, and identify the exact Apriso release/version you are running (in your admin UI or vendor documentation).
- Determine whether the Apriso server is reachable from the public internet (for example, from outside your network) and whether any management/API endpoints are exposed.
- If you are exposed to the internet, restrict access immediately (allow only approved IPs/VPN/VLANs) until the vendor provides a fix.
- Watch for an official vendor patch or upgrade guidance for CVE-2026-9695 for your specific DELMIA Apriso release line, and plan to upgrade as soon as a fixed version is published.
- If the system cannot be isolated and you cannot confirm exposure is limited, treat this as a high-risk exposure case and coordinate with your IT/vendor to implement compensating controls (segmentation, strict firewalling, and access logging) immediately.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-9695 and every CVE in our database. Create a free account — no credit card required.
Create Free Account