BE-2026-0003: XML External Entity Vulnerability in ProjectWise Design Integration Server
Bentley ID: BE-2026-0003
CVE ID:
Severity: 7.5
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Publication date: 2026-09-10
Revision date: 2026-09-10
Summary
ProjectWise Design Integration Server may be affected by an XML External Entity vulnerability. Exploiting this vulnerability could allow an unauthenticated remote attacker to trigger unsafe XML parsing, potentially resulting in information disclosure.
Details
ProjectWise Design Integration Server contains an XML External Entity vulnerability (CWE-611). In some circumstances, a remote unauthenticated attacker who can reach an affected server may cause unsafe XML parsing. Successful exploitation may result in information disclosure.
Affected Versions
| Applications | Affected Versions | Mitigated Versions |
| ProjectWise Design Integration Server | <23.6.3.35 | >=23.6.3.35 |
| ProjectWise Design Integration Server | <25.0.1.8097 | >=25.0.1.8097 |
Recommended Mitigations
Revision History
| Date | Description |
| 2026-09-10 | First version of this advisory |
