External risk intelligence

GEOVIA Geospatial Data Manager Code Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-84154

GEOVIA Geospatial Data Manager is enterprise software used for specialized data management. While it operates over a network, it is typically deployed within internal engineering or corporate environments rather than as a public-facing internet service. Public internet exposure is plausible in some specific enterprise configurations but is not the standard deployment pattern.

Code Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A code injection vulnerability has been identified in GEOVIA Geospatial Data Manager software, potentially allowing unauthorized attackers to execute arbitrary code on servers. This issue affects specific releases of the 3DEXPERIENCE platform and warrants attention to understand its relevance to our environment.

  • Code execution flaw in data management software.
  • Verify if our specific software version is impacted.
  • Assess potential for unauthorized code execution.

Attack Path

How an attacker could exploit the issue

An attacker with some level of user access could potentially target the GEOVIA Geospatial Data Manager. By sending specially crafted data, the attacker could exploit a code injection flaw, leading to the execution of arbitrary commands on the server. This could ultimately compromise the server's integrity and data.

  • Requires authenticated user access.
  • Exploited by sending malicious data.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A code injection vulnerability in GEOVIA Geospatial Data Manager could allow an authenticated attacker to execute arbitrary code on the server. This may impact the integrity and availability of the system.

  • Server-side code execution.
  • Attacker injects malicious code.
  • System compromise and data loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

Technical leaders should engage application owners responsible for GEOVIA Geospatial Data Manager and their platform or infrastructure teams to understand the scope of this critical code injection vulnerability. The immediate first step is to identify all instances of the affected software, confirm their network reachability and business criticality, and then assign an accountable owner for remediation planning.

  • Application owners should lead remediation efforts.
  • Verify all affected software instances exist.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is GEOVIA Geospatial Data Manager?

GEOVIA Geospatial Data Manager is a specialized component within the 3DEXPERIENCE platform. Organizations use it to handle complex geospatial data workflows, such as mining and geological modeling, typically within engineering or corporate data environments.

What does CWE-94 code injection mean in CVE-2026-84154?

CWE-94 refers to improper control of generation of code. In this CVE, it means the software fails to properly filter input, allowing an attacker to insert and execute their own unauthorized commands on the host server rather than just processing intended data.

How is this code injection vulnerability triggered?

An attacker triggers this flaw by sending specially crafted data packets to the server. Importantly, this requires the attacker to have an existing level of authenticated user access to the system; simply being an unauthenticated guest is insufficient to initiate the attack.

Is my server at risk for CVE-2026-84154?

According to Halo Surface Signal, this software is typically deployed within internal engineering or corporate networks. While public internet exposure is possible in unique setups, this is not the standard configuration, which often limits the immediate reach of external threats.

What steps should I take if I run this software?

Begin by auditing your infrastructure to locate all instances of the affected 3DEXPERIENCE platform releases. Coordinate with application owners to assess the network placement of these servers and establish an accountable team to manage patching or configuration updates once available.

References