
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-10789 is a critical code injection vulnerability (CWE-94) in the Model Context Protocol (MCP) extension of Autodesk Fusion Desktop. A maliciously crafted webpage, when visited by a user running Autodesk Fusion Desktop with the MCP extension enabled, can trigger arbitrary code execution with the privileges of the current user. Affected versions span Fusion Desktop 2703.1.11 up to (but not including) 2703.1.20. The vulnerability was published on June 22, 2026, with a patch available as of the same date. It carries a CVSS v3.1 base score of 9.6 (Critical) (GitHub Advisory, Autodesk Advisory).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), where the MCP extension in Autodesk Fusion Desktop fails to properly neutralize externally-influenced input received from a maliciously crafted webpage. The attack vector is network-based and requires no privileges, but does require user interaction — specifically, a victim must visit an attacker-controlled or compromised webpage while Fusion Desktop is running with the MCP extension active. The changed scope (S:C) in the CVSS vector indicates that the vulnerability's impact extends beyond the vulnerable component itself, potentially affecting other system resources. No public proof-of-concept code has been identified at this time (GitHub Advisory, Autodesk Advisory).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the victim's system with the privileges of the currently logged-in user, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive files, modify or delete data, install malware, or use the compromised system as a pivot point for lateral movement within a network. The changed scope indicates that resources beyond the Fusion application itself — such as the underlying operating system — may be affected (GitHub Advisory, Autodesk Advisory).
cmd.exe, powershell.exe, bash, curl, wget); unusual process creation events associated with the Fusion MCP extension.Autodesk has released a patched version of Fusion Desktop (2703.1.20) that addresses this vulnerability. Users should update Autodesk Fusion Desktop to version 2703.1.20 or later using the official Autodesk Fusion Client Downloader for Windows or macOS. As an interim workaround if immediate patching is not possible, users should disable the MCP extension within Autodesk Fusion Desktop. Additionally, users should be advised to avoid visiting untrusted or suspicious webpages while Fusion Desktop is running with the MCP extension enabled (Autodesk Advisory, GitHub Advisory).
The vulnerability received standard aggregation coverage across vulnerability tracking platforms including Vulners, VulDB, EUVD (ENISA), and CVEFeed shortly after disclosure on June 22, 2026. Social media mentions were observed on Bluesky and Mastodon (infosec.exchange), with the cybersecurity community noting the critical severity and the MCP extension attack surface as points of interest. CYFIRMA included the vulnerability in a weekly intelligence digest published in early July 2026. No major independent technical write-ups or significant vendor statements beyond the official Autodesk advisory have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."