Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x
Summary
| CVE | CVE-2026-7858 |
|---|---|
| State | PUBLISHED |
| Assigner | 3DS |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-01 09:16:20 UTC |
| Updated | 2026-06-01 17:57:39 UTC |
| Description | A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.003430000 probability, percentile 0.571470000 (date 2026-06-01)
Problem Types: CWE-502 | CWE-502 CWE-502 Deserialization of Untrusted Data
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Dassault Systmes | Teamwork Cloud - Standard Edition | affected No Magic Release 2022x Golden No Magic Release 2022x Refresh2 HF3 custom | Not specified |
| CNA | Dassault Systmes | Teamwork Cloud - Standard Edition | affected No Magic Release 2024x Golden No Magic Release 2024x Refresh3 HF1 custom | Not specified |
| CNA | Dassault Systmes | Teamwork Cloud - Standard Edition | affected No Magic Release 2026x Golden No Magic Release 2026x Golden HF2 custom | Not specified |
| CNA | Dassault Systmes | Teamwork Cloud - Business Edition | affected No Magic Release 2022x Golden No Magic Release 2022x Refresh2 HF3 custom | Not specified |
| CNA | Dassault Systmes | Teamwork Cloud - Business Edition | affected No Magic Release 2024x Golden No Magic Release 2024x Refresh3 HF1 custom | Not specified |
| CNA | Dassault Systmes | Teamwork Cloud - Business Edition | affected No Magic Release 2026x Golden No Magic Release 2026x Golden HF2 custom | Not specified |
| CNA | Dassault Systmes | Teamwork Cloud - Business Pro Edition | affected No Magic Release 2022x Golden No Magic Release 2022x Refresh2 HF3 custom | Not specified |
| CNA | Dassault Systmes | Teamwork Cloud - Business Pro Edition | affected No Magic Release 2024x Golden No Magic Release 2024x Refresh3 HF1 custom | Not specified |
| CNA | Dassault Systmes | Teamwork Cloud - Business Pro Edition | affected No Magic Release 2026x Golden No Magic Release 2026x Golden HF2 custom | Not specified |
| CNA | Dassault Systmes | Teamwork Cloud - Enterprise Edition | affected No Magic Release 2022x Golden No Magic Release 2022x Refresh2 HF3 custom | Not specified |
| CNA | Dassault Systmes | Teamwork Cloud - Enterprise Edition | affected No Magic Release 2024x Golden No Magic Release 2024x Refresh3 HF1 custom | Not specified |
| CNA | Dassault Systmes | Teamwork Cloud - Enterprise Edition | affected No Magic Release 2026x Golden No Magic Release 2026x Golden HF2 custom | Not specified |
| CNA | Dassault Systmes | Magic Collaboration Studio | affected CATIA Magic Release 2022x Golden CATIA Magic Release 2022x Refresh2 HF3 custom | Not specified |
| CNA | Dassault Systmes | Magic Collaboration Studio | affected CATIA Magic Release 2024x Golden CATIA Magic Release 2024x Refresh3 HF1 custom | Not specified |
| CNA | Dassault Systmes | Magic Collaboration Studio | affected CATIA Magic Release 2026x Golden CATIA Magic Release 2026x Golden HF2 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.3ds.com/trust-center/security/security-advisories/cve-2026-7858 | [email protected] | www.3ds.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Tyler Harkness (en)
There are currently no legacy QID mappings associated with this CVE.