---
cve: "CVE-2026-7858"
severity: "CRITICAL"
cvss: 9.8
epss: "0.5%"
vendor: "Dassault Systèmes"
kev: false
exploited: false
published: "2026-06-01 09:16:20"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-22T03:35:59+02:00"
---

# CVE-2026-7858

> 9.8 CRITICAL

## Beschreibung

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://www.3ds.com/trust-center/security/security-advisories/cve-2026-7858>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-7858) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
