CVE-2026-35383
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
02/04/2026
Last modified:
02/04/2026
Description
Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated attacker could use this token to enumerate or delete certain assets. As of 2026-03-27, the token is no longer present in the web pages and cannot be used to enumerate or delete assets.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
6.50
Severity 3.x
MEDIUM



