CVE Explorer
CVE-2026-11756
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Station Launcher App in 3DEXPERIENCE platform","vendor":"Dassault Systèmes","versions":[{"lessThanOrEqual":"Release 3DEXPERIENCE R2023x.FP.CFA.2613","status":"affected","version":"Release 3DEXPERIENCE R2023x Golden","versionType":"custom"},{"lessThanOrEqual":"Release 3DEXPERIENCE R2024x.FP.CFA.2615","status":"affected","version":"Release 3DEXPERIENCE R2024x Golden","versionType":"custom"},{"lessThanOrEqual":"Release 3DEXPERIENCE R2025x.FP.CFA.2628","status":"affected","version":"Release 3DEXPERIENCE R2025x Golden","versionType":"custom"},{"lessThanOrEqu…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1c3c9e6c0db9bd8efc42c83ef8231740a68ccbf574a558b952b743a6dd40d460 · sha256:7e3568e3ee7a2008… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1c3c9e6c0db9bd8efc42c83ef8231740a68ccbf574a558b952b743a6dd40d460 · sha256:7e3568e3ee7a2008… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-502","description":"CWE-502 Deserialization of Untrusted Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1c3c9e6c0db9bd8efc42c83ef8231740a68ccbf574a558b952b743a6dd40d460 · sha256:7e3568e3ee7a2008… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.3ds.com/trust-center/security/security-advisories/cve-2026-11756"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1c3c9e6c0db9bd8efc42c83ef8231740a68ccbf574a558b952b743a6dd40d460 · sha256:7e3568e3ee7a2008… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.