Junglewise Threat Intelligence

CVE-2026-0533: Autodesk Fusion Stored XSS in delete confirmation dialog

CVE-2026-0533 · Severity: high · CVSS 8.1 · Published 2026-01-22

Vendors: Autodesk.

Executive brief

Autodesk Fusion, a popular 3D design and engineering software, is affected by a security flaw that allows attackers to hide malicious code within a design's name. If a user attempts to delete a design with such a name and interacts with the confirmation dialog, the attacker could gain unauthorized access to local files or run malicious software on the user's computer. This could lead to the theft of intellectual property or a full compromise of the user's workstation.

Technical details

A Stored Cross-site Scripting (XSS) vulnerability exists in the Autodesk Fusion desktop application due to improper neutralization of input in design names. An attacker can craft a design name containing a malicious HTML payload; when this name is rendered in the delete confirmation dialog and clicked by a user, the payload executes. Because the desktop application likely uses a web-based UI framework with elevated privileges, this XSS can be escalated to read local files or execute arbitrary code in the context of the current process. The vulnerability is tracked as CVE-2026-0533 and is fixed in version 2606.1.21.

Affected products

  • Autodesk Fusion up to (excluding) 2606.1.21

Timeline

  • 2026-01-22: disclosed
  • 2026-01-22: advisory
  • 2026-01-30: patched: NIST analysis confirmed fix version 2606.1.21

References