Junglewise Threat Intelligence

CVE-2026-5120: Dassault Systèmes BIOVIA Workbook race condition

CVE-2026-5120 · Severity: high · CVSS 8.1 · Published 2026-07-01

Vendors: Dassault SystèMes.

Executive brief

BIOVIA Workbook, a collaborative scientific electronic laboratory notebook, is affected by a security flaw that could allow one user to access another user's private data. This occurs due to a timing issue in how the software handles simultaneous requests, potentially leading to unauthorized data exposure or modification. Organizations using this software for research and development should ensure they are running the latest patched versions to protect sensitive intellectual property.

Technical details

A race condition (CWE-362) exists in BIOVIA Workbook due to improper synchronization during concurrent execution using shared resources. The vulnerability affects releases from 2021 through 2026. An authenticated attacker can exploit this flaw over the network by sending specifically timed requests to the application. Successful exploitation allows the attacker to bypass intended access controls and view or manipulate data belonging to other users. The CVSS 3.1 score is 8.1, reflecting high impact on confidentiality and integrity with low attack complexity, though it requires basic user privileges.

Affected products

  • Dassault Systèmes BIOVIA Workbook Release 2021 through Release 2026

Timeline

  • 2026-07-01: advisory: Initial advisory published by Dassault Systèmes and NVD.

References