Junglewise Threat Intelligence

CVE-2026-0534: Autodesk Fusion Stored XSS in part attributes

CVE-2026-0534 · Severity: high · CVSS 8.1 · Published 2026-01-22

Vendors: Autodesk.

Executive brief

Autodesk Fusion, a popular 3D design and engineering software, is affected by a security flaw that allows attackers to embed malicious code within a part's attributes. If a user interacts with this malicious content, an attacker could gain unauthorized access to local files or execute harmful commands on the user's computer. This could lead to the theft of intellectual property or a full compromise of the user's workstation.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Autodesk Fusion desktop application due to improper neutralization of input in part attributes (CWE-79). An attacker can inject a malicious HTML payload into a part's attribute; when a victim clicks on this attribute, the payload executes within the context of the application. This can be leveraged to achieve local file disclosure or arbitrary code execution in the context of the current process. The vulnerability is exploitable over the network with user interaction required. Autodesk has released a patch in version 2606.1.21 to address this issue.

Affected products

  • Autodesk Fusion versions up to (excluding) 2606.1.21

Timeline

  • 2026-01-22: disclosed
  • 2026-01-22: advisory
  • 2026-01-30: patched: NIST analysis confirmed patch version 2606.1.21

References