CVE-2026-7406 – Autodesk Revit
“A malicious design file can turn routine content processing into code execution, data exposure, or application failure.”
Autodesk Revit is affected by four file-processing vulnerabilities. CVE-2026-11803 has a CVSS score of 7.8, High severity, and can allow code execution, sensitive data exposure, or a crash through a malicious PDF. CVE-2026-1289 has a CVSS score of 7.8, High severity, and can trigger similar impacts through a use-after-free condition. CVE-2026-7406 has a CVSS score of 7.8, High severity, and can allow arbitrary code execution through a crafted BMP file. CVE-2026-8325 has a CVSS score of 7.8, High severity, and can cause code execution, data corruption, or a crash through a malicious PDF.
The Revit security update addresses these unsafe file-processing paths and reduces the risk from malicious PDF and BMP content.
Key Details
- Affected Product
- Autodesk Advance Steel
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-822