CVE-2026-7858 PUBLISHED

Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x

Assigner: 3DS
Reserved: 05.05.2026 Published: 01.06.2026 Updated: 01.06.2026

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Dassault Systèmes
Product Teamwork Cloud - Standard Edition
Versions Default: unaffected
  • affected from No Magic Release 2022x Golden to No Magic Release 2022x Refresh2 HF3 (incl.)
  • affected from No Magic Release 2024x Golden to No Magic Release 2024x Refresh3 HF1 (incl.)
  • affected from No Magic Release 2026x Golden to No Magic Release 2026x Golden HF2 (incl.)
Vendor Dassault Systèmes
Product Teamwork Cloud - Business Edition
Versions Default: unaffected
  • affected from No Magic Release 2022x Golden to No Magic Release 2022x Refresh2 HF3 (incl.)
  • affected from No Magic Release 2024x Golden to No Magic Release 2024x Refresh3 HF1 (incl.)
  • affected from No Magic Release 2026x Golden to No Magic Release 2026x Golden HF2 (incl.)
Vendor Dassault Systèmes
Product Teamwork Cloud - Business Pro Edition
Versions Default: unaffected
  • affected from No Magic Release 2022x Golden to No Magic Release 2022x Refresh2 HF3 (incl.)
  • affected from No Magic Release 2024x Golden to No Magic Release 2024x Refresh3 HF1 (incl.)
  • affected from No Magic Release 2026x Golden to No Magic Release 2026x Golden HF2 (incl.)
Vendor Dassault Systèmes
Product Teamwork Cloud - Enterprise Edition
Versions Default: unaffected
  • affected from No Magic Release 2022x Golden to No Magic Release 2022x Refresh2 HF3 (incl.)
  • affected from No Magic Release 2024x Golden to No Magic Release 2024x Refresh3 HF1 (incl.)
  • affected from No Magic Release 2026x Golden to No Magic Release 2026x Golden HF2 (incl.)
Vendor Dassault Systèmes
Product Magic Collaboration Studio
Versions Default: unaffected
  • affected from CATIA Magic Release 2022x Golden to CATIA Magic Release 2022x Refresh2 HF3 (incl.)
  • affected from CATIA Magic Release 2024x Golden to CATIA Magic Release 2024x Refresh3 HF1 (incl.)
  • affected from CATIA Magic Release 2026x Golden to CATIA Magic Release 2026x Golden HF2 (incl.)

Credits

  • Tyler Harkness finder

References

Problem Types

  • CWE-502 Deserialization of Untrusted Data CWE