🔐 CVE Alert

CVE-2026-3476

HIGH 7.8

Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

A Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code on the user's machine while opening a specially crafted file.

CWE CWE-94
Vendor dassault systèmes
Product solidworks desktop
Published Mar 16, 2026
Last Updated Mar 17, 2026
Stay Ahead of the Next One

Get instant alerts for dassault systèmes solidworks desktop

Be the first to know when new high vulnerabilities affecting dassault systèmes solidworks desktop are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Dassault Systèmes / SOLIDWORKS Desktop
Release 2025 SP0 ≤ Release 2025 SP5 Release 2026 SP0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
3ds.com: https://www.3ds.com/trust-center/security/security-advisories/cve-2026-3476

Credits

Simón Marcote