Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-11756Deserialization RCE in 3DEXPERIENCE Station Launcher

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.

View on NVD

Analysis

La aplicación Station Launcher de la plataforma 3DEXPERIENCE permite la ejecución remota de código sin autenticación debido a una vulnerabilidad de deserialización de datos. Un atacante puede comprometer totalmente el sistema de forma remota sin necesidad de credenciales ni interacción previa del usuario. Se recomienda actualizar inmediatamente las instalaciones del ecosistema R2023x a R2026x para mitigar este riesgo crítico.

Relevant roles

CyberSecurityBackendWindowsJava

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-502

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.

Published: 7/28/2026, 8:17:14 AM
Last modified: 7/28/2026, 8:17:14 AM

References

HomeEventsBlogResourcesCoursesTeam