A critical vulnerability (CVE-2026-11756) has been identified in the Station Launcher App component of the 3DEXPERIENCE platform. The flaw stems from improper validation of serialized data inputs, enabling unauthenticated attackers to exploit deserialization mechanisms and achieve remote code execution. This vulnerability impacts all releases from 3DEXPERIENCE R2023x through R2026x. Successful exploitation could allow attackers to execute arbitrary commands with the privileges of the affected service, potentially leading to full system compromise. Given the CVSS score of 10.0, this vulnerability poses an immediate high-risk threat to exposed systems. Organizations utilizing the affected software versions are strongly advised to apply vendor-released security patches immediately. As a mitigation measure, network administrators should block untrusted inbound connections to the Station Launcher App service until patches can be deployed. No public exploits have been reported at this time, but the potential for remote code execution without authentication underscores the urgency of remediation.
CRITICAL
CVSS 10.0
CVE-2026-11756
2026-08-14
Critical RCE Vulnerability in 3DEXPERIENCE Platform (CVE-2026-11756)
A critical remote code execution vulnerability in the Station Launcher App of the 3DEXPERIENCE platform allows unauthenticated attackers to execute arbitrary code via deserialization of untrusted data. Affects versions R2023x through R2026x. Immediate patching required.