Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated attacker could use this token to enumerate or delete certain assets. As of 2026-03-27, the token is no longer present in the web pages and cannot be used to enumerate or delete assets.
References
Configurations
No configuration.
History
02 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-02 20:16
Updated : 2026-04-03 16:10
NVD link : CVE-2026-35383
Mitre link : CVE-2026-35383
CVE.ORG link : CVE-2026-35383
JSON object : View
Products Affected
No product.
CWE
CWE-540
Inclusion of Sensitive Information in Source Code
