Description
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
Published: 2026-07-28
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Station Launcher App of the 3DEXPERIENCE platform allows deserialization of untrusted data, which can enable an unauthenticated attacker to execute arbitrary code. The flaw is a classic Deserialization of Untrusted Data weakness, classified as CWE-502, and it could compromise confidentiality, integrity, and availability of the affected application and any systems it orchestrates.

Affected Systems

The flaw affects Dassault Systèmes' Station Launcher App within the 3DEXPERIENCE platform for all releases from R2023x through R2026x. Users running any of these releases should check whether their instance includes the unpatched component.

Risk and Exploitability

The vulnerability scores a maximum CVSS score of 10, indicating critical severity. The EPSS score of less than 1% suggests a low current exploitation probability, and it is not listed in CISA’s KEV catalog. However, a remote attacker could potentially exploit the flaw by sending crafted serialized data to the shared service, bypassing authentication controls. The likely attack vector is network-based delivery of malicious payloads to the Station Launcher App over the exposed interfaces.

Generated by OpenCVE AI on August 3, 2026 at 15:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update released by Dassault Systèmes that patches the Station Launcher App deserialization flaw.
  • Restrict inbound traffic to the Station Launcher App, limiting access to trusted internal users or applying firewall rules that block unauthenticated connections from external networks.
  • Enforce strict input validation or disable any features that deserialize data from untrusted sources within the application configuration.

Generated by OpenCVE AI on August 3, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dassault Systèmes
Dassault Systèmes station Launcher App In 3dexperience Platform
Vendors & Products Dassault Systèmes
Dassault Systèmes station Launcher App In 3dexperience Platform

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
Title Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dassault Systèmes Station Launcher App In 3dexperience Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: 3DS

Published:

Updated: 2026-07-28T12:53:11.927Z

Reserved: 2026-06-09T07:11:51.888Z

Link: CVE-2026-11756

cve-icon Vulnrichment

Updated: 2026-07-28T12:53:04.739Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-28T08:17:14.007

Modified: 2026-07-30T19:11:32.053

Link: CVE-2026-11756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:30:03Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data