CVE-2026-11756RCE por deserialización en 3DEXPERIENCE Station Launcher
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
Ver en NVDAnálisis
La aplicación Station Launcher de la plataforma 3DEXPERIENCE permite la ejecución remota de código sin autenticación debido a una vulnerabilidad de deserialización de datos. Un atacante puede comprometer totalmente el sistema de forma remota sin necesidad de credenciales ni interacción previa del usuario. Se recomienda actualizar inmediatamente las instalaciones del ecosistema R2023x a R2026x para mitigar este riesgo crítico.
Roles relevantes
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-502EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.