
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0535 is a Stored Cross-Site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A maliciously crafted HTML payload embedded in a component's description field can be triggered when a user clicks on it, potentially allowing an attacker to read local files or execute arbitrary code within the context of the running process. All Autodesk Fusion versions prior to 2606.1.21 are affected. The CVE was published on January 22, 2026, with a patch released by January 30, 2026. It carries a CVSS v3.1 base score of 8.1 (High), as assigned by Autodesk (Autodesk Advisory, NVD).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored/persistent variant (NVD). The root cause is insufficient sanitization of HTML content stored in component description fields within the Autodesk Fusion desktop application, which renders user-supplied markup in a context that allows script execution. Because Fusion is a desktop application (likely using an embedded web rendering engine such as Electron or a WebView), stored XSS can escape typical browser sandboxing constraints and interact with the local filesystem or execute native code. Exploitation requires user interaction — specifically, a victim must click on a maliciously crafted component description — but no authentication or elevated privileges are required of the attacker to plant the payload (Autodesk Advisory).
Successful exploitation allows a malicious actor to read sensitive local files accessible to the Fusion process and execute arbitrary code with the privileges of the current user running the application (Autodesk Advisory, NVD). The CVSS assessment reflects high confidentiality and high integrity impact, with no availability impact. In a design or engineering environment where Autodesk Fusion is commonly used, exploitation could expose proprietary CAD/design files, credentials stored locally, or enable further lateral movement if the attacker achieves persistent code execution on the victim's workstation.
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.008% (0.000080), indicating a very low probability of exploitation in the near term. Exploitation requires an attacker to first store a malicious payload in a component description accessible to the target user, which may require some level of access to shared Fusion project resources.
cmd.exe, powershell.exe, bash, curl, python) that are not part of normal Fusion operation.Autodesk has released a patch in Fusion version 2606.1.21, which resolves this vulnerability; all users running earlier versions should update immediately (Autodesk Advisory). Updated installers are available via the Autodesk Fusion Client Downloader for both Windows and macOS. As interim mitigations, users should exercise caution when opening component descriptions from untrusted or external sources, restrict Fusion project sharing to trusted collaborators, and monitor for suspicious process or file activity on systems running Fusion.
The vulnerability was noted in a CISA weekly vulnerability bulletin (week of January 19, 2026) and picked up by security aggregators including Red Packet Security and VulnDB (CISA Bulletin). No significant independent researcher commentary or social media discussion has been identified beyond standard CVE tracking and aggregation activity. The low EPSS score and absence of public PoC suggest limited community concern at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."