{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-11756","assignerOrgId":"f5a594e6-46a7-4e60-8a08-0a786e70e433","state":"PUBLISHED","assignerShortName":"3DS","dateReserved":"2026-06-09T07:11:51.888Z","datePublished":"2026-07-28T07:35:17.764Z","dateUpdated":"2026-07-28T12:53:11.927Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f5a594e6-46a7-4e60-8a08-0a786e70e433","shortName":"3DS","dateUpdated":"2026-07-28T07:35:17.764Z"},"title":"Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-502","description":"CWE-502 Deserialization of Untrusted Data","type":"CWE"}]}],"affected":[{"vendor":"Dassault Systèmes","product":"Station Launcher App in 3DEXPERIENCE platform","versions":[{"status":"affected","version":"Release 3DEXPERIENCE R2023x Golden","lessThanOrEqual":"Release 3DEXPERIENCE R2023x.FP.CFA.2613","versionType":"custom"},{"status":"affected","version":"Release 3DEXPERIENCE R2024x Golden","lessThanOrEqual":"Release 3DEXPERIENCE R2024x.FP.CFA.2615","versionType":"custom"},{"status":"affected","version":"Release 3DEXPERIENCE R2025x Golden","lessThanOrEqual":"Release 3DEXPERIENCE R2025x.FP.CFA.2628","versionType":"custom"},{"status":"affected","version":"Release 3DEXPERIENCE R2026x Golden","lessThanOrEqual":"Release 3DEXPERIENCE R2026x.FP.CFA.2624","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.","supportingMedia":[{"type":"text/html","base64":false,"value":"A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution."}]}],"references":[{"url":"https://www.3ds.com/trust-center/security/security-advisories/cve-2026-11756"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10,"baseSeverity":"CRITICAL"}}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-28T12:51:20.407907Z","id":"CVE-2026-11756","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-28T12:53:11.927Z"}}]}}