Description
A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to access unauthorized data from another user.
Published: 2026-07-01
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition flaw in Dassault Systèmes’ BIOVIA Workbook releases from 2021 through 2026 permits a user to read data belonging to another user, resulting weakness is classified as CWE‑362, indicating a concurrency bug that can be triggered by overlapping operations within the same application instance.

Affected Systems

Dassault Systèmes’ BIOVIA Workbook, including all releases from 2021 to 2026.

Risk and Exploitability

The CVSS score of 8.1 marks the vulnerability as high severity, while the EPSS score of less than 1 % suggests that publicly available exploitation is very unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves attackers executing concurrent actions within the same installation, such as manipulating user sessions or performing simultaneous data operations; however, no publicly documented exploits exist.

Generated by OpenCVE AI on July 21, 2026 at 14:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any released patch for BIOVIA Workbook or upgrade to a version issued after 2026 that removes the race condition
  • Enforce least‑privilege by limiting user permissions so that accounts can access only their own data
  • Enable detailed audit logging of read operations and routinely review logs for evidence of cross‑user data access

Generated by OpenCVE AI on July 21, 2026 at 14:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Dassault Systèmes
Dassault Systèmes biovia Workbook
Vendors & Products Dassault Systèmes
Dassault Systèmes biovia Workbook

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to access unauthorized data from another user.
Title Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026
Weaknesses CWE-362
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Dassault Systèmes Biovia Workbook
cve-icon MITRE

Status: PUBLISHED

Assigner: 3DS

Published:

Updated: 2026-07-01T13:36:37.270Z

Reserved: 2026-03-30T07:15:44.963Z

Link: CVE-2026-5120

cve-icon Vulnrichment

Updated: 2026-07-01T13:36:33.556Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T15:00:09Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')