Junglewise Threat Intelligence

CVE-2026-0535: Autodesk Fusion stored XSS in component description

CVE-2026-0535 · Severity: high · CVSS 8.1 · Published 2026-01-22

Vendors: Autodesk.

Executive brief

Autodesk Fusion, a popular 3D design and engineering software, is affected by a security vulnerability that allows attackers to embed malicious code within a component's description. If a user clicks on this description, the attacker could gain unauthorized access to local files or execute malicious commands on the user's computer. This could lead to the theft of sensitive design data or a full compromise of the workstation.

Technical details

A Stored Cross-site Scripting (XSS) vulnerability exists in the Autodesk Fusion desktop application due to improper neutralization of input in a component's description field (CWE-79). An attacker can inject a malicious HTML payload into this field; when a victim views and clicks the description, the payload executes within the context of the application. Because the desktop application likely uses a web-based rendering engine with elevated privileges, this XSS can be escalated to read local system files or achieve arbitrary code execution (RCE). The vulnerability is exploitable over the network with user interaction and has been addressed in version 2606.1.21.

Affected products

  • Autodesk Fusion versions up to (excluding) 2606.1.21

Timeline

  • 2026-01-22: disclosed
  • 2026-01-22: advisory: NVD Published Date
  • 2026-01-30: patched: NIST analysis identified fix version 2606.1.21

References