Description
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Published: 2026-08-06
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Malicious PDF files trigger an out‑of‑bounds read inside Autodesk Revit when the file is parsed, allowing an attacker to cause a crash, leak sensitive data, or execute arbitrary code in the current process context. The weakness is described by CWE‑125 and represents an untrusted input validation flaw that can be abused by supplying a deliberately crafted PDF that reads past the bounds of a buffer during parsing.

Affected Systems

Autodesk Revit products, specifically the 2026 and 2027 releases, are affected. Users of these versions who open externally sourced PDF documents may be exposed to the exploit. No specific sub‑version fixes are listed, so all builds under those release lines should be considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.8 classifies the vulnerability as high severity. EPSS data is not available, but the lack of a public KEV listing does not diminish the potential risk, especially in environments where PDFs are routinely processed or integrated. The attack likely requires the victim to open a malicious PDF or otherwise trigger the parsing routine, which could be delivered via email attachments, shared network drives, or automated import processes. Because the flaw can lead to arbitrary code execution, prompt remediation is advised.

Generated by OpenCVE AI on August 6, 2026 at 23:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Autodesk Revit security patch that addresses the PDF parsing issue from the Autodesk security advisory.
  • Restrict or disable automatic rendering of PDF files in Revit, and avoid opening untrusted PDFs.
  • Run Revit with the least privilege necessary and consider sandboxing the application when working with external documents.

Generated by OpenCVE AI on August 6, 2026 at 23:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Title PDF File Parsing Out-of-Bounds Read Vulnerability in Autodesk Revit
First Time appeared Autodesk
Autodesk revit
Weaknesses CWE-125
CPEs cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk revit
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-08-06T15:58:36.195Z

Reserved: 2026-06-09T15:00:58.771Z

Link: CVE-2026-11803

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T00:00:05Z

Weaknesses