Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-11756RCE por deserialización en 3DEXPERIENCE Station Launcher

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.

Ver en NVD

Análisis

La aplicación Station Launcher de la plataforma 3DEXPERIENCE permite la ejecución remota de código sin autenticación debido a una vulnerabilidad de deserialización de datos. Un atacante puede comprometer totalmente el sistema de forma remota sin necesidad de credenciales ni interacción previa del usuario. Se recomienda actualizar inmediatamente las instalaciones del ecosistema R2023x a R2026x para mitigar este riesgo crítico.

Roles relevantes

CyberSecurityBackendWindowsJava

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-502

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.

Publicada: 28/7/2026, 8:17:14
Última modificación: 28/7/2026, 8:17:14

Referencias

InicioEventosBlogRecursosCursosEquipo