
CVE-2026-35383 Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated attacker could use this token to enumerate or del… https://www.cve.org/CVERecord?id=CVE-2026-35383
Post summary
The content details how CVE-2026-35383 exposes Cesium ion access tokens in Bentley iTwin Platform web pages, enabling unauthenticated attackers to enumerate resources, but no exploit, patch, or active exploitation reports are provided.
