Home

Description

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution.

PUBLISHED Reserved 2026-05-05 | Published 2026-06-01 | Updated 2026-06-01 | Assigner 3DS




CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-502 Deserialization of Untrusted Data

Product status

Default status
unaffected

No Magic Release 2022x Golden (custom)
affected

No Magic Release 2024x Golden (custom)
affected

No Magic Release 2026x Golden (custom)
affected

Default status
unaffected

No Magic Release 2022x Golden (custom)
affected

No Magic Release 2024x Golden (custom)
affected

No Magic Release 2026x Golden (custom)
affected

Default status
unaffected

No Magic Release 2022x Golden (custom)
affected

No Magic Release 2024x Golden (custom)
affected

No Magic Release 2026x Golden (custom)
affected

Default status
unaffected

No Magic Release 2022x Golden (custom)
affected

No Magic Release 2024x Golden (custom)
affected

No Magic Release 2026x Golden (custom)
affected

Default status
unaffected

CATIA Magic Release 2022x Golden (custom)
affected

CATIA Magic Release 2024x Golden (custom)
affected

CATIA Magic Release 2026x Golden (custom)
affected

Credits

Tyler Harkness finder

References

www.3ds.com/...er/security/security-advisories/cve-2026-7858

cve.org (CVE-2026-7858)

nvd.nist.gov (CVE-2026-7858)

Download JSON