CVE-2026-77644CWE-306CWE-620
CVE-2026-77644
published August 21, 2026
What it is
A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.
The record
Technical detail
- CVSS
- 9.3 · NONE
- CVSS v4.0
- 9.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/RE:M/U:Red
- EPSS
- 0.00313 · 23.8th percentile
- Weaknesses
- CWE-306 · Missing Authentication for Critical Function; CWE-620 · Unverified Password Change
- Published
- 2026-08-21T02:18Z
References (1)
EPSS history
Timeline