CVE-2026-10789
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-10789 is a critical code injection vulnerability (CWE-94) in the Model Context Protocol (MCP) extension of Autodesk Fusion Desktop. A maliciously crafted webpage, when visited by a user running Autodesk Fusion Desktop with the MCP extension enabled, can trigger arbitrary code execution with the privileges of the current user. Affected versions span Fusion Desktop 2703.1.11 up to (but not including) 2703.1.20. The vulnerability was published on June 22, 2026, with a patch available as of the same date. It carries a CVSS v3.1 base score of 9.6 (Critical) (GitHub Advisory, Autodesk Advisory).

Technical details

The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), where the MCP extension in Autodesk Fusion Desktop fails to properly neutralize externally-influenced input received from a maliciously crafted webpage. The attack vector is network-based and requires no privileges, but does require user interaction — specifically, a victim must visit an attacker-controlled or compromised webpage while Fusion Desktop is running with the MCP extension active. The changed scope (S:C) in the CVSS vector indicates that the vulnerability's impact extends beyond the vulnerable component itself, potentially affecting other system resources. No public proof-of-concept code has been identified at this time (GitHub Advisory, Autodesk Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the victim's system with the privileges of the currently logged-in user, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive files, modify or delete data, install malware, or use the compromised system as a pivot point for lateral movement within a network. The changed scope indicates that resources beyond the Fusion application itself — such as the underlying operating system — may be affected (GitHub Advisory, Autodesk Advisory).

Exploitation steps

  1. Reconnaissance: Identify targets who use Autodesk Fusion Desktop (e.g., engineers, designers, manufacturing professionals) and confirm that the MCP extension is likely enabled in their environment.
  2. Craft malicious webpage: Develop a webpage containing a specially crafted payload that exploits the code injection flaw in the Fusion MCP extension. The payload is designed to be processed by the MCP extension when the browser or web content interacts with the locally running Fusion Desktop application.
  3. Deliver the malicious URL: Lure the target user to visit the malicious webpage via phishing email, social engineering, or a watering-hole attack targeting industry-specific forums or resources frequented by Fusion users.
  4. Trigger code injection: When the victim visits the page with Autodesk Fusion Desktop running and the MCP extension enabled, the malicious webpage triggers the MCP extension's vulnerable code path, injecting and executing arbitrary code.
  5. Achieve code execution: The injected code executes with the privileges of the current user, enabling the attacker to establish persistence, exfiltrate data, deploy additional payloads, or move laterally within the network (GitHub Advisory, Autodesk Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the Autodesk Fusion Desktop process to unknown or suspicious external IP addresses or domains; unusual HTTP/HTTPS traffic originating from the Fusion process.
  • Process: Unexpected child processes spawned by the Autodesk Fusion Desktop application (e.g., cmd.exe, powershell.exe, bash, curl, wget); unusual process creation events associated with the Fusion MCP extension.
  • File System: New or modified files in Fusion installation directories or user profile directories created by the Fusion process; unexpected scripts, executables, or configuration files dropped on disk.
  • Logs: Application event logs showing unusual activity from the Fusion MCP extension; browser or system logs recording visits to suspicious or unknown URLs immediately preceding anomalous Fusion behavior.

Mitigation and workarounds

Autodesk has released a patched version of Fusion Desktop (2703.1.20) that addresses this vulnerability. Users should update Autodesk Fusion Desktop to version 2703.1.20 or later using the official Autodesk Fusion Client Downloader for Windows or macOS. As an interim workaround if immediate patching is not possible, users should disable the MCP extension within Autodesk Fusion Desktop. Additionally, users should be advised to avoid visiting untrusted or suspicious webpages while Fusion Desktop is running with the MCP extension enabled (Autodesk Advisory, GitHub Advisory).

Community reactions

The vulnerability received standard aggregation coverage across vulnerability tracking platforms including Vulners, VulDB, EUVD (ENISA), and CVEFeed shortly after disclosure on June 22, 2026. Social media mentions were observed on Bluesky and Mastodon (infosec.exchange), with the cybersecurity community noting the critical severity and the MCP extension attack surface as points of interest. CYFIRMA included the vulnerability in a weekly intelligence digest published in early July 2026. No major independent technical write-ups or significant vendor statements beyond the official Autodesk advisory have been identified at this time.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16412CRITICAL9.8
  • NixOS logoNixOS
  • rhel10::thunderbird-flatpak
NoYesJul 21, 2026
CVE-2026-16411CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026
CVE-2026-16410CRITICAL9.8
  • NixOS logoNixOS
  • mozjs38
NoYesJul 21, 2026
CVE-2026-16408CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026
CVE-2026-16409HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management