CVE-2026-35383
Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated attacker could use this
CVSS
6.5
Medium
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Apr 2, 2026 · Last modified: Jul 24, 2026 · CWE-540
0.3%EPSS · 30 days0.3%
2026-07-262026-08-23
Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated attacker could use this token to enumerate or delete certain assets. As of 2026-03-27, the token is no longer present in the web pages and cannot be used to enumerate or delete assets.