
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7454 is a memory corruption vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted WRL (VRML World) file, enabling arbitrary code execution in the context of the current process. It affects Autodesk 3ds Max versions 2026 (prior to 2026.1) and 2027 (prior to 2027.1). The vulnerability was published on May 26, 2026, with patches made available the same day. It carries a CVSS v3.1 base score of 7.8 (High) (Autodesk Advisory, GitHub Advisory).
The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input / Classic Buffer Overflow): the WRL file parser in 3ds Max copies input data into a buffer without validating that the input size does not exceed the destination buffer's capacity, resulting in memory corruption. The attack vector is local, requiring no privileges but requiring user interaction — specifically, a victim must open a maliciously crafted WRL file. Exploitation triggers an out-of-bounds write condition (also estimated as CWE-787) that can corrupt process memory in a manner sufficient to redirect code execution (GitHub Advisory, Autodesk Advisory).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the Autodesk 3ds Max process on the victim's system, resulting in high confidentiality, integrity, and availability impact. An attacker who achieves code execution in this context could access sensitive project files, install malware, or pivot to other resources accessible by the user account running 3ds Max. The scope is limited to the affected process and user context, with no scope change, but full compromise of the local user session is possible (Autodesk Advisory, GitHub Advisory).
cmd.exe, powershell.exe, curl, mshta.exe); 3ds Max process crashing or exhibiting abnormal CPU/memory usage upon opening a WRL file.3dsmax.exe with faulting module related to WRL/VRML parsing; unexpected process creation events (Event ID 4688) with 3dsmax.exe as parent process.3dsmax.exe to unknown external IP addresses or domains, particularly shortly after opening a WRL file.Autodesk has released patched versions: 3ds Max 2026.1 and 3ds Max 2027.1, which address this vulnerability. Users should update immediately via Autodesk Access or the Autodesk desktop app. As a workaround, avoid opening WRL files from untrusted or unverified sources, and consider restricting WRL file type associations or implementing file validation controls in environments where 3ds Max is deployed (Autodesk Advisory, GitHub Advisory).
The vulnerability received routine coverage from vulnerability tracking platforms including VulnDB, CVEFeed, and Vulners shortly after disclosure. A brief mention appeared on Mastodon via The Hacker Wire account. No significant researcher commentary, vendor blog posts, or major media coverage has been identified beyond standard vulnerability database entries and the CISA weekly bulletin inclusion (CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."