Executive brief
Dassault Systèmes Teamwork Cloud and Magic Collaboration Studio, which are used for collaborative model-based systems engineering and design, contain a critical security flaw. An unauthorized attacker can remotely execute malicious code on the server without needing any login credentials. This could lead to a total compromise of the server, including the theft of sensitive engineering designs, data destruction, or a complete shutdown of collaborative operations.
Technical details
A Deserialization of Untrusted Data vulnerability (CWE-502) exists in Teamwork Cloud and Magic Collaboration Studio. The flaw allows an unauthenticated attacker to send specially crafted serialized objects over the network, which the application then processes without sufficient validation. Successful exploitation leads to remote code execution (RCE) with the privileges of the application service. The vulnerability affects No Magic Release 2022x through 2026x and CATIA Magic Release 2022x through 2026x. Users are advised to consult the Dassault Systèmes trust center for remediation information.
Affected products
- Dassault Systèmes Teamwork Cloud (Standard, Business, Business Pro, Enterprise Editions) No Magic Release 2022x through No Magic Release 2026x
- Dassault Systèmes (CATIA Magic) Magic Collaboration Studio CATIA Magic Release 2022x through CATIA Magic Release 2026x
Timeline
- 2026-06-01: advisory: Initial advisory published by Dassault Systèmes and NVD