CVE-2026-11756

Dassault Systèmes · 3DEXPERIENCE platform (Station Launcher App)

A deserialization of untrusted data vulnerability in the 3DEXPERIENCE Station Launcher App allows unauthenticated remote code execution.

Executive summary

A critical deserialization vulnerability in the Dassault Systèmes 3DEXPERIENCE platform allows unauthenticated remote attackers to execute arbitrary code with full system privileges.

Vulnerability

This is a deserialization of untrusted data flaw (CWE-502) within the Station Launcher App. The vulnerability is exploitable by unauthenticated remote attackers, as confirmed by the CVSS vector AV:N/PR:N.

Business impact

The ability for an unauthenticated attacker to execute remote code poses a catastrophic risk to the integrity, confidentiality, and availability of the 3DEXPERIENCE platform. Given the CVSS score of 10.0, this vulnerability could lead to total system compromise, unauthorized access to sensitive product design data, and potential lateral movement within the corporate network.

Remediation

Immediate Action: Update the Dassault Systèmes Station Launcher App to the latest version provided by the vendor. Refer to the official security advisory for specific build requirements.

Proactive Monitoring: Monitor server logs for suspicious deserialization attempts or unusual process execution patterns originating from the Station Launcher service.

Compensating Controls: Deploy a Web Application Firewall (WAF) with inspection capabilities for serialized objects to potentially block malicious payloads if immediate patching is not feasible.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical severity and the potential for full system compromise, organizations running the affected versions of the 3DEXPERIENCE platform must prioritize this update. Immediate patching is the only effective way to mitigate the risk of remote code execution.