External risk intelligence

Teamwork Cloud and Magic Collaboration Studio Deserialization Vulnerability Allows Unauthenticated Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-7858

Teamwork Cloud and Magic Collaboration Studio are typically deployed as centralized, server-based collaboration platforms that require network connectivity for distributed team access, making them frequently reachable as service endpoints in enterprise environments.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in No Magic and CATIA Magic collaboration software that could allow an unauthenticated attacker to execute arbitrary code remotely. This issue arises from the deserialization of untrusted data, presenting a significant risk if the affected systems are accessible from external networks.

  • Unauthenticated remote code execution flaw.
  • Affects collaboration platforms requiring network access.
  • Confirm relevance and exposure to collaboration tools.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted data over the network to an exposed Teamwork Cloud or Magic Collaboration Studio instance. This data would be deserialized by the application, triggering the vulnerability and potentially allowing the attacker to execute arbitrary code on the server.

  • Network access required.
  • Deserialization of untrusted data.
  • Unauthenticated remote code execution.

Live Threat

Current exploitation, exposure, and threat context

A deserialization vulnerability in Teamwork Cloud and Magic Collaboration Studio could allow an unauthenticated attacker to execute arbitrary code remotely. This could affect system integrity and confidentiality when the software is accessible over a network.

  • System integrity and confidentiality.
  • Unauthenticated remote code execution.
  • Unauthorized access and control.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners for Teamwork Cloud and Magic Collaboration Studio are responsible for addressing this critical vulnerability. The first step is to identify all instances of the affected software, confirm network reachability, and assess business criticality to prioritize remediation efforts.

  • Confirm application and infrastructure ownership.
  • Verify affected systems' reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Teamwork Cloud and Magic Collaboration Studio?

These are centralized, server-based platforms used by engineering and design teams to manage complex models and collaborate on system architecture. They act as a single source of truth for distributed teams, often integrating with model-based systems engineering (MBSE) tools to synchronize large-scale design data across an organization.

How does the deserialization vulnerability in CVE-2026-7858 work?

This vulnerability, classified as CWE-502, occurs when the application processes data from an untrusted source without proper validation. Because the software expects to reconstruct objects from this data, an attacker can supply malicious input that the system inadvertently executes as code, effectively granting them control over the server.

Do I need to be logged in to trigger CVE-2026-7858?

No, this vulnerability allows unauthenticated access. An attacker does not need legitimate user credentials to initiate the attack. The flaw is triggered simply by sending specially crafted network traffic to the affected service; interactions that do not involve sending malicious serialized data packets do not trigger this specific bug.

Why is CVE-2026-7858 considered an external risk?

Halo Surface Signal labels this as an external risk because these platforms are built for team connectivity and are frequently deployed as reachable service endpoints. If your instance is accessible from an external network, it may be exposed to remote attackers attempting to exploit this deserialization flaw.

What should I do if I run this software?

Begin by auditing your infrastructure to locate all active instances of Teamwork Cloud and Magic Collaboration Studio. Verify whether these instances are reachable over a network and assess their business impact. Focus your immediate attention on securing systems that are internet-facing while you coordinate with your IT and security teams to apply the necessary security updates.

References