Description
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Published: 2026-08-06
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A maliciously crafted PDF file, when processed through Autodesk Revit, triggers an out‑of‑bounds write that can corrupt memory. An attacker exploiting this flaw can cause the application to crash, corrupt data, or potentially execute arbitrary code in the context of the running process. The weakness is a classic buffer overwrite, classified as CWE‑787.

Affected Systems

Revit editions 2026 and 2027 from Autodesk are affected. The vulnerability applies to any instance of the product that uses the default PDF parser when opening or importing PDF files.

Risk and Exploitability

With a CVSS score of 7.8, the flaw presents a medium‑high risk profile. No EPSS value is published, so the current propensity for exploitation is unclear, and the vulnerability does not appear in the CISA KEV catalog. The exploit is likely local or arises when a user opens a malicious PDF, either from a local file or a network location, making it possible for an attacker to trigger the memory corruption simply by supplying a specially crafted PDF to an affected environment.

Generated by OpenCVE AI on August 7, 2026 at 01:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Autodesk Revit security patch described in the Autodesk Security Advisory ADK-SA-2026-0011.
  • Avoid opening PDF files from untrusted or unknown sources; treat PDFs as untrusted content.
  • Run Revit in a sandbox or restrict the application to a least‑privilege user context to contain potential code execution.

Generated by OpenCVE AI on August 7, 2026 at 01:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Title PDF File Parsing Out-of-Bounds Write Vulnerability in Autodesk Revit
First Time appeared Autodesk
Autodesk revit
Weaknesses CWE-787
CPEs cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk revit
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-08-06T15:58:02.242Z

Reserved: 2026-05-11T14:02:24.198Z

Link: CVE-2026-8325

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:15:05Z

Weaknesses