Article - CS474818

Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition

Modified: 26-Aug-2026   


Applies To

  • Windchill Risk and Reliability Enterprise Edition (Formerly Relex) 11.1 to 13.1

 

Excludes:

  • Windchill Risk and Reliability (WRR) Team Edition
  • Windchill
  • FlexPLM

Description

  • Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition
  • CVE-2026-77644 has been reported for this WRR vulnerability 
  • Related CWEs
     
    • CWE-306 – Missing Authentication for Critical Function
      The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. 
    • CWE-620 – Unverified Password Change
      The application lets a user change a password without verifying the original/current password (or otherwise confirming the requester's identity). This enables an attacker who has temporary access to a session — or who can exploi
This is a printer-friendly version of Article 474818 and may be out of date. For the latest version click CS474818