Description
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.
Published: 2026-07-29
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A maliciously crafted DWG or DXF file, when parsed by Autodesk AutoCAD, can trigger an out-of-bounds read. This vulnerability allows read access to memory beyond the intended buffer, potentially revealing sensitive information or causing the application to crash. The weakness is a classic buffer over-read (CWE‑125).

Affected Systems

Affected products include Autodesk AutoCAD 2027, Autodesk AutoCAD LT 2027, and Autodesk DWG TrueView 2027. No prior version is listed as affected, so any installation of the 2027 editions is considered vulnerable.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of real-world exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, based on a user opening a malicious DWG or DXF file. While the vulnerability does not provide remote code execution, it can still lead to denial of service or accidental disclosure of confidential data. Consequently, organizations should treat this as a risk that could impact system availability and confidentiality but is low in exploitation likelihood.

Generated by OpenCVE AI on August 3, 2026 at 13:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest AutoCAD or related product release that resolves the out‑of‑bounds read, following Autodesk’s 2026‑0009 advisory
  • If an update cannot be applied immediately, restrict the opening of DWG/DXF files to trusted sources and isolate the application in a sandboxed or network‑segmented environment
  • Keep monitoring Autodesk’s security channels for any subsequent patches or advisories and apply them as soon as they become available

Generated by OpenCVE AI on August 3, 2026 at 13:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:2026:*:*:*:*:*:*:*

Wed, 29 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.
Title DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
First Time appeared Autodesk
Autodesk autocad
Autodesk autocad Lt
Autodesk dwg Trueview
Weaknesses CWE-125
CPEs cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk autocad
Autodesk autocad Lt
Autodesk dwg Trueview
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

Autodesk Advance Steel Autocad Autocad Architecture Autocad Electrical Autocad Lt Autocad Map 3d Autocad Mechanical Autocad Mep Autocad Plant 3d Civil 3d Dwg Trueview
cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-08-07T18:29:17.003Z

Reserved: 2026-07-21T13:11:00.568Z

Link: CVE-2026-16465

cve-icon Vulnrichment

Updated: 2026-07-29T15:55:15.474Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T16:17:50.530

Modified: 2026-08-11T01:38:30.517

Link: CVE-2026-16465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:30:04Z

Weaknesses