Junglewise Threat Intelligence

CVE-2026-16783: Autodesk 3ds Max out-of-bounds write in ABC file parsing

CVE-2026-16783 · Severity: high · CVSS 7.8 · Published 2026-08-24

Technologies: Autodesk 3ds Max. Vendors: Autodesk.

Executive brief

Autodesk 3ds Max is a professional 3D modeling and animation software widely used in film, game development, and design studios. A crafted ABC file can trigger an out-of-bounds memory write when parsed by the application, allowing an attacker to crash the program, corrupt data, or execute arbitrary code if the user opens a malicious file.

Technical details

This vulnerability is an out-of-bounds write in the ABC (Alembic) file parser of Autodesk 3ds Max. The vulnerability exists in the file parsing logic when processing a maliciously crafted ABC file. An attacker can exploit this by distributing a malicious ABC file that, when opened in 3ds Max, triggers an out-of-bounds write condition. No authentication or special privileges are required—only user interaction (opening the file) is needed. Successful exploitation can lead to arbitrary code execution in the context of the 3ds Max process, data corruption, or denial of service through application crash. A patch is expected to be available from Autodesk.

Affected products

  • Autodesk 3ds Max

Timeline

  • 2026-08-24: disclosed

References

Related threats