CVE-2026-77644

Windchill: Missing Authentication for Critical Function (CVE-2026-77644)

criticalEPSS 0.4%

Affected

  • PTC/Windchill range_unparsed *..Risk and Reliability (WRR) Enterprise Edition <13.1.0.1
  • PTC/Windchill = PDMLink..PDMLink

Description

A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

PTCWindchill
PDMLinkRisk and Reliability (WRR) Enterprise Edition <13.1.0.1

Metrics

9.3
Source: cna-v4
35.3 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
critical
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-20 21:54 UTC
CWE-306, CWE-620

Weakness classes (CWE)

  • CWE-306Base

    Missing Authentication for Critical Function

    The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

    cwe.mitre.org →
  • CWE-620Base

    Unverified Password Change

    When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-22 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-77644","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…