Executive brief
A critical security flaw has been identified in the Station Launcher App within the Dassault Systèmes 3DEXPERIENCE platform, a suite used for product design and engineering. This vulnerability allows an unauthorized person to remotely take control of the system without needing a username or password. An attacker could use this access to steal sensitive design data, disrupt operations, or gain a foothold in the corporate network.
Technical details
A Deserialization of Untrusted Data vulnerability (CWE-502) exists in the Station Launcher App component of the Dassault Systèmes 3DEXPERIENCE platform. The flaw allows an unauthenticated remote attacker to send specially crafted serialized data to the application, which, when processed, results in arbitrary code execution with the privileges of the application. The vulnerability is highly critical as it requires no user interaction or prior authentication and has a wide impact across releases R2023x through R2026x. Remediation information is available through the vendor's trust center.
Affected products
- Dassault Systèmes Station Launcher App in 3DEXPERIENCE platform Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x
Timeline
- 2026-07-27: advisory: Original vendor advisory published by Dassault Systèmes
- 2026-07-28: disclosed: CVE published to NVD dataset