CRITICAL🇵🇱 Wersja polska

CVE-2026-10789

CVSS 9.6v3.1pub. 2026-06-22upd. 2026-06-24

A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.

🤖 AI Analysis
How it works

When a user has Autodesk Fusion Desktop running with the MCP extension enabled and visits a maliciously crafted website, the MCP extension processes content or requests from that site in a way that allows arbitrary code injection and execution (CWE-94 — improper control of code generation). The attack does not require interaction beyond the victim visiting the page. Network vector (AV:N) with no authentication requirement (PR:N) and scope extending beyond the application (S:C) makes this vulnerability particularly dangerous.

Impact

An attacker can execute arbitrary code with the privileges of the currently logged-in operating system user, which may lead to system takeover, data theft, or installation of malicious software.

Mitigation & patch

Apply patches available from the manufacturer according to references (https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0008). Until updating, it is recommended to disable the MCP extension in Autodesk Fusion Desktop. Client updates are available at the addresses indicated in the references for Windows and macOS systems.

Who is affected

Autodesk Fusion Desktop with MCP extension enabled — specific versions indicated in the manufacturer's references (adsk-sa-2026-0008)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Autodesk Fusion

    APP
    Autodesk
    < 2703.1.20
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-4369HIGH7.1same product

A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation ...

CVE-2026-4345HIGH7.1same product

A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-si...

CVE-2026-4344HIGH7.1same product

A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog a...

CVE-2026-0535HIGH8.1same product

A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a S...

CVE-2026-0533HIGH8.1same product

A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and ...