Description
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.
Published: 2026-08-06
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use‑After‑Free vulnerability. The attacker can cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process. This flaw stems from improper memory management during PDF parsing and is classified as CWE‑416. Those who can supply or deliver a crafted PDF that the affected Autodesk products will open are the primary risk group. The vulnerability can compromise confidentiality, integrity, and availability of the application and the underlying system.

Affected Systems

Autodesk AutoCAD, AutoCAD LT, and Revit releases from 2024 through 2027 are affected. Users of any of these versions on supported platforms may be vulnerable if they open a maliciously crafted PDF file. The vulnerability resides in the core PDF parsing component of these applications.

Risk and Exploitability

The CVSS base score is 7.8, indicating high severity. The EPSS score is <1% (≈0.00141), suggesting a very low baseline exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by providing a malicious PDF to any user who opens it; therefore, the likely attack vector is a local or distant document open. Once the attack succeeds, the attacker can gain code execution privileges with the same rights as the affected process, potentially compromising the underlying operating system.

Generated by OpenCVE AI on September 21, 2026 at 07:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available Autodesk security update for affected AutoCAD, AutoCAD LT, and Revit releases from 2024 through 2027.
  • If no patch is available, disable or restrict the PDF import feature so that only trusted users can open PDFs, or use a sandboxed environment to process PDFs.
  • Implement monitoring of Revit logs for abnormal crashes or memory errors following PDF ingestion to detect missed exploitation.

Generated by OpenCVE AI on September 21, 2026 at 07:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process. A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.
Title PDF File Parsing Use-After-Free Vulnerability in Autodesk Revit PDF File Parsing Vulnerabilities in Certain Autodesk Desktop Products

Thu, 17 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Autodesk autocad
Autodesk autocad Lt
CPEs cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk autocad
Autodesk autocad Lt

Fri, 04 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*

Fri, 07 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.
Title PDF File Parsing Use-After-Free Vulnerability in Autodesk Revit
First Time appeared Autodesk
Autodesk revit
Weaknesses CWE-416
CPEs cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk revit
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Autodesk Autocad Autocad Lt Revit
cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-09-17T13:49:16.359Z

Reserved: 2026-01-21T14:43:33.946Z

Link: CVE-2026-1289

cve-icon Vulnrichment

Updated: 2026-08-07T15:22:09.744Z

cve-icon NVD

Status : Modified

Published: 2026-08-06T22:17:00.373

Modified: 2026-09-17T14:17:12.393

Link: CVE-2026-1289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:30:08Z

Weaknesses