CVE-2026-3476 PUBLISHED

Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026

Assigner: 3DS
Reserved: 03.03.2026 Published: 16.03.2026 Updated: 16.03.2026

A Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code on the user's machine while opening a specially crafted file.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor Dassault Systèmes
Product SOLIDWORKS Desktop
Versions Default: unaffected
  • affected from Release 2025 SP0 to Release 2025 SP5 (incl.)
  • Version Release 2026 SP0 is affected

Credits

  • Simón Marcote finder

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE