Description
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
Published: 2026-08-11
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reported weakness is a deserialization of untrusted data flaw that allows an external actor to modify serialized input and have it executed by SIMULIA Execution Engine. Because the vulnerability does not require prior authentication, an attacker can inject arbitrary code into the engine’s runtime and potentially gain full control over the host system. The weakness is identified as CWE‑502, a common issue where deserializing untrusted data leads to arbitrary code execution.

Affected Systems

Dassault Systèmes SIMULIA Execution Engine in releases from 2023 to 2026 is affected. No specific patch level is listed, so any version within this release range requires remediation.

Risk and Exploitability

The CVSS score of 10 indicates a critical severity, while no EPSS score is published and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the flaw permits unauthenticated remote code execution and the engine is designed for deployment in varied environments, the likelihood of exploitation is high in practice. Attackers would likely exploit remote accessible services that deserialize input without validating the payload.

Generated by OpenCVE AI on August 11, 2026 at 23:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Dassault Systèmes security update for SIMULIA Execution Engine or upgrade to a release beyond 2026.
  • Restrict network exposure of the Engine’s endpoints by enabling firewall rules or VPN isolation so that only trusted hosts can reach the deserialization service.
  • Replace or disable the vulnerable deserialization mechanism; where possible, use a safe serialization library that validates input before processing.

Generated by OpenCVE AI on August 11, 2026 at 23:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Dassault Systèmes
Dassault Systèmes simulia Execution Engine
Vendors & Products Dassault Systèmes
Dassault Systèmes simulia Execution Engine

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
Title Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dassault Systèmes Simulia Execution Engine
cve-icon MITRE

Status: PUBLISHED

Assigner: 3DS

Published:

Updated: 2026-08-11T19:44:09.908Z

Reserved: 2026-07-24T13:46:13.875Z

Link: CVE-2026-17061

cve-icon Vulnrichment

Updated: 2026-08-11T19:44:05.360Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T15:17:27.783

Modified: 2026-08-28T15:42:20.060

Link: CVE-2026-17061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:54:20Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data