
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0659 is an Out-of-Bounds Write vulnerability affecting Autodesk Arnold (USD for Arnold) and Autodesk 3ds Max, triggered by loading or importing a maliciously crafted USD file. Successful exploitation allows an attacker to execute arbitrary code in the context of the current process. Affected versions include USD for Arnold / Arnold versions prior to 7.4.4.2, and 3ds Max versions 2026.2 through 2026.3.2 (fixed in 2026.3.2). The vulnerability was published on February 4, 2026, and carries a CVSS v3.1 base score of 7.8 (High) (Autodesk Advisory, Feedly).
The root cause is an Out-of-Bounds Write (CWE-787) triggered during the parsing or import of a specially crafted Universal Scene Description (USD) file. When the malicious file is loaded into Autodesk Arnold or 3ds Max, insufficient bounds checking allows memory to be written beyond the bounds of an allocated buffer, enabling code execution. The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction (UI:R) — specifically, a user must open or import the crafted USD file. No public proof-of-concept exploit code has been identified at this time (Autodesk Advisory, Feedly).
Successful exploitation results in high impact to confidentiality, integrity, and availability — an attacker can achieve arbitrary code execution in the context of the user running Autodesk Arnold or 3ds Max. This could allow the attacker to access sensitive files, modify project data, install malware, or pivot to other systems accessible from the compromised workstation. The scope is limited to the affected process and host, but the full triad of CIA impacts makes this a significant risk for creative and engineering environments where USD files are routinely exchanged (Autodesk Advisory, Feedly).
3dsmax.exe) or Arnold renderer processes (e.g., kick.exe), such as cmd.exe, powershell.exe, curl, or scripting interpreters.3dsmax.exe or Arnold renderer processes to unknown external IP addresses or domains, particularly after loading a USD file.Autodesk has released patched versions addressing this vulnerability: USD for Arnold / Arnold 7.4.4.2 and 3ds Max 2026.3.2. Users should update to these versions immediately via Autodesk Access or the Autodesk desktop app. As a workaround, users should avoid opening USD files from untrusted or unverified sources until patching is complete. Organizations should also consider restricting the exchange of USD files through unvetted channels in production pipelines (Autodesk Advisory).
The vulnerability received brief coverage from automated security news aggregators and social media accounts such as The Hacker Wire on Mastodon and Bluesky shortly after disclosure. No significant independent researcher commentary or in-depth technical analysis has been publicly identified. Community reaction appears limited, consistent with the low EPSS score and absence of public exploit code (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."