CVE-2026-7858
Awaiting Analysis
Awaiting Analysis - Queue
Deserialization Flaw in Teamwork Cloud Allows RCE
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: Dassault Systèmes
Description
Description
A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| no_magic | teamwork_cloud | From 2022x (inc) to 2026x (inc) |
| catia_magic | magic_collaboration_studio | From 2022x (inc) to 2026x (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |