CVE-2026-3476: Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026
Published Mar 16, 2026
·Updated
A Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code on the user's machine while opening a specially crafted file.
Affected Software
3 affected components
Dassault Systèmes SOLIDWORKS Desktop>=2025<=2026
3DS Solidworks>=2025<2026
3DS Solidworks=2026-sp0
Event History
Mar 16, 2026
CVE Published
via MITRE·11:48 AM
Data Sourced
via MITRE·11:48 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-3476?
CVE-2026-3476 is identified as a high-severity code injection vulnerability.
2
How do I fix CVE-2026-3476?
To mitigate CVE-2026-3476, users should update their SOLIDWORKS Desktop software to the latest version provided by Dassault Systèmes.
3
What versions of SOLIDWORKS Desktop are affected by CVE-2026-3476?
CVE-2026-3476 affects SOLIDWORKS Desktop versions from Release 2025 through Release 2026.
4
What can attackers do with CVE-2026-3476?
Attackers exploiting CVE-2026-3476 can execute arbitrary code on a user's machine.
5
How does the CVE-2026-3476 vulnerability work?
CVE-2026-3476 works by allowing specially crafted inputs to execute malicious code when users open certain files in SOLIDWORKS Desktop.