Description
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.
Published: 2026-08-06
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious PDF can trigger a use‑after‑free bug in Autodesk Revit, potentially allowing the attacker to crash the application, leak data, or run code in the Revit process. The vulnerability stems from improper memory management when parsing PDF files and is classified as CWE‑416. Those who can supply or deliver a crafted PDF that Revit will open are the primary risk groups. This flaw can cause significant compromise of confidentiality, integrity, and availability for users and the system running Revit.

Affected Systems

Autodesk Revit versions 2026 and 2027 are affected. Users running these versions on any supported platform may be vulnerable if they open an attacker‑crafted PDF file. The vulnerability is present the core PDF parsing component of Revit.

Risk and Exploitability

The CVSS base score is 7.8, indicating high severity. EPSS is not available, so the current exploit probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by providing a malicious PDF to any user who opens it; therefore, the likely attack vector is a local or distant document open. Once the attack succeeds, the attacker can gain code execution privileges with the same rights as the Revit process, potentially compromising the underlying operating system.

Generated by OpenCVE AI on August 6, 2026 at 23:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Autodesk Revit security update for the affected 2026 or 2027 release.
  • If no patch is available, disable or restrict the PDF import feature so that only trusted users can open PDFs, or use a sandboxed environment to process PDFs.
  • Implement monitoring of Revit logs for abnormal crashes or memory errors following PDF ingestion to detect missed exploitation.

Generated by OpenCVE AI on August 6, 2026 at 23:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.
Title PDF File Parsing Use-After-Free Vulnerability in Autodesk Revit
First Time appeared Autodesk
Autodesk revit
Weaknesses CWE-416
CPEs cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk revit
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-08-06T15:57:13.827Z

Reserved: 2026-01-21T14:43:33.946Z

Link: CVE-2026-1289

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T23:30:05Z

Weaknesses