Junglewise Threat Intelligence

CVE-2026-14255: Autodesk IFC parser uncontrolled recursion denial of service

CVE-2026-14255 · Severity: medium · CVSS 5.5 · Published 2026-09-02

Technologies: Autodesk <UNKNOWN>. Vendors: Autodesk.

Executive brief

Autodesk products that parse IFC (Industry Foundation Classes) files can be forced to crash when processing a maliciously crafted file. IFC files are standard formats used in construction and building design workflows. An attacker can cause a denial-of-service by tricking a user into opening a specially crafted IFC file, disrupting work and potentially affecting project schedules.

Technical details

This vulnerability is an uncontrolled recursion issue in the IFC file parser used by certain Autodesk products. The parser fails to properly limit recursion depth when processing nested structures within maliciously crafted IFC files, allowing an attacker to trigger stack overflow or excessive resource consumption. Exploitation requires user interaction: a victim must open a specially crafted IFC file using a vulnerable Autodesk application. The attack results in application termination (denial-of-service); no authentication is required and the attack vector is local. Patches are expected to be available from Autodesk.

Affected products

  • Autodesk <UNKNOWN>

Timeline

  • 2026-09-02: disclosed

References

Related threats