
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0662 is an Untrusted Search Path (CWE-426) vulnerability in Autodesk 3ds Max that allows arbitrary code execution when a user opens a maliciously crafted project directory containing a .max file. The vulnerability affects Autodesk 3ds Max versions 2026 through 2026.3.2 (exclusive). It was published on February 4, 2026, with a patch made available on February 6, 2026. The CVSS v3.1 base score is 7.8 (High) (Autodesk Advisory, Red Hat CVE).
The root cause is an Untrusted Search Path (CWE-426), mapped to CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) and MITRE ATT&CK technique T1574.007 (Path Interception by PATH Environment Variable). When Autodesk 3ds Max opens a .max file, it resolves dependent libraries or resources using a search path that can be influenced by the contents of the project directory. An attacker who controls the project directory can place a malicious DLL or executable in a location that the application searches before legitimate system paths, causing it to be loaded and executed. Exploitation requires user interaction — specifically, a victim must open the crafted .max file — but no privileges are required (Autodesk Advisory, Red Hat CVE).
Successful exploitation results in arbitrary code execution in the context of the current user process, yielding high confidentiality, integrity, and availability impact. An attacker can gain unauthorized access to sensitive data on the system, modify or delete files, and potentially use the compromised workstation as a pivot point for lateral movement within the network. The attack is local in vector, meaning the malicious project directory must be delivered to and opened by the victim, but the consequences are equivalent to full user-level system compromise (Autodesk Advisory).
.max file alongside a malicious DLL or executable named to match a library that Autodesk 3ds Max searches for during file loading (e.g., a plugin or helper DLL)..max file within Autodesk 3ds Max (e.g., by presenting it as a client asset or template)..max project directories, particularly files with names matching known 3ds Max plugins or system libraries; newly created or modified files in the 3ds Max installation or user profile directories shortly after opening a .max file.3dsmax.exe process (e.g., cmd.exe, powershell.exe, curl.exe, or unknown executables); DLLs loaded by 3ds Max from non-standard paths (e.g., project directories rather than the application's install directory).3dsmax.exe to external IP addresses or domains, particularly shortly after a .max file is opened.3dsmax.exe as the parent and unexpected child processes; Sysmon Event ID 7 (Image Loaded) showing DLLs loaded from project directories.Autodesk has released a patch in version 2026.3.2; users running any 3ds Max 2026 version prior to 2026.3.2 should upgrade immediately (Autodesk Advisory). As interim workarounds, organizations should restrict users from opening .max files received from untrusted or unverified sources, and implement controls (e.g., application whitelisting, endpoint DLP) to prevent loading of unauthorized DLLs. User awareness training on the risks of opening files from unknown sources is also recommended.
Coverage of CVE-2026-0662 has been limited to automated vulnerability tracking platforms and security news aggregators such as The Hacker Wire, Red Packet Security, and Tenable's plugin pipeline. No notable independent researcher commentary or significant social media discussion has been identified beyond routine CVE publication notices (Red Hat CVE, Autodesk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."