CVE-2026-17061 PUBLISHED

Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026

Assigner: 3DS
Reserved: 24.07.2026 Published: 11.08.2026 Updated: 11.08.2026

A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor Dassault Systèmes
Product SIMULIA Execution Engine
Versions Default: unaffected
  • Version Release 2023 Golden is affected
  • affected from Release 2024 Golden to Release 2024 FP.CFA.2615 (incl.)
  • affected from Release 2025 Golden to Release 2025 FP.CFA.2628 (incl.)
  • affected from Release 2026 Golden to Release 2026 FP.CFA.2624 (incl.)

References

Problem Types

  • CWE-502 Deserialization of Untrusted Data CWE