Deserialization Vulnerability in Station Launcher App on 3DEXPERIENCE Platform
CVE-2026-11756

10CRITICAL

What is CVE-2026-11756?

A deserialization vulnerability has been identified in the Station Launcher App within the 3DEXPERIENCE platform, spanning from releases R2023x to R2026x. This flaw allows attackers to exploit untrusted data, potentially leading to unauthorized remote code execution without authentication. Proper mitigation strategies should be employed to safeguard against potential exploitation.

Affected Version(s)

Station Launcher App in 3DEXPERIENCE platform Release 3DEXPERIENCE R2023x Golden

Station Launcher App in 3DEXPERIENCE platform Release 3DEXPERIENCE R2024x Golden

Station Launcher App in 3DEXPERIENCE platform Release 3DEXPERIENCE R2025x Golden

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.