Description
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Published: 2026-08-06
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

An out‑of‑bounds read in the PDF parsing component of Autodesk AutoCAD, AutoCAD LT, and Revit allows a maliciously crafted PDF file to trigger a crash, leak memory contents, or ultimately execute arbitrary code in the context of the running process. The flaw is classified as CWE‑125, representing a failure to properly validate input bounds during memory access.

Affected Systems

All Autodesk desktop products listed in the CVE—AutoCAD, AutoCAD LT, and Revit—covering 2024 through 2027 releases are affected. The vulnerability applies to the general product lines with these release years, meaning users with any of these versions and both standard and LT editions should consider themselves vulnerable until a corrective update is installed. Specific sub‑versions beyond the listed years are not documented, so any build within the affected ranges is presumed impacted.

Risk and Exploitability

The CVSS base score of 7.8 marks the issue as high severity, while the EPSS score below 1% indicates a low but non‑zero likelihood of exploitation at the current moment. Because the attack vector hinges on opening a malicious PDF, it can be delivered via email attachments, shared network files, or automated import processes, which are typical in design and engineering environments. The absence of a CISA KEV listing does not mitigate the risk; any process that renders PDFs from user input remains a potential entry point. Prompt application of vendor patches and disabling automatic PDF rendering are recommended to mitigate these risks.

Generated by OpenCVE AI on September 21, 2026 at 07:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Autodesk security update that addresses the PDF parsing flaw for AutoCAD, AutoCAD LT, and Revit, following the guidance in the official Autodesk security advisory.
  • Disable or restrict automatic PDF rendering within Autodesk applications, and avoid opening PDFs from untrusted sources.
  • Run Autodesk products with the least privilege necessary and consider sandboxing or isolation techniques when processing external documents.

Generated by OpenCVE AI on September 21, 2026 at 07:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Title PDF File Parsing Out-of-Bounds Read Vulnerability in Autodesk Revit PDF File Parsing Out-of-Bounds Read Vulnerability in in Certain Autodesk Desktop Products

Thu, 17 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Autodesk autocad
Autodesk autocad Lt
CPEs cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk autocad
Autodesk autocad Lt

Fri, 04 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*

Fri, 07 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Title PDF File Parsing Out-of-Bounds Read Vulnerability in Autodesk Revit
First Time appeared Autodesk
Autodesk revit
Weaknesses CWE-125
CPEs cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk revit
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Autodesk Autocad Autocad Lt Revit
cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-09-17T13:52:08.090Z

Reserved: 2026-06-09T15:00:58.771Z

Link: CVE-2026-11803

cve-icon Vulnrichment

Updated: 2026-08-07T15:27:54.297Z

cve-icon NVD

Status : Modified

Published: 2026-08-06T22:16:44.967

Modified: 2026-09-17T14:17:11.953

Link: CVE-2026-11803

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:45:11Z

Weaknesses