CVE-2026-3476

A Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code on the user's machine while opening a specially crafted file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:3ds:solidworks:*:*:*:*:*:*:*:*
cpe:2.3:a:3ds:solidworks:2026:sp0:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-16 14:19

Updated : 2026-06-17 10:43


NVD link : CVE-2026-3476

Mitre link : CVE-2026-3476

CVE.ORG link : CVE-2026-3476


JSON object : View

Products Affected

3ds

  • solidworks
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')