CVE-2026-7406 – Autodesk Revit

CVSS 7.8 IMPORTANT High with EoP or RCE – Expedited Deployment

“A malicious design file can turn routine content processing into code execution, data exposure, or application failure.”

Autodesk Revit is affected by four file-processing vulnerabilities. CVE-2026-11803 has a CVSS score of 7.8, High severity, and can allow code execution, sensitive data exposure, or a crash through a malicious PDF. CVE-2026-1289 has a CVSS score of 7.8, High severity, and can trigger similar impacts through a use-after-free condition. CVE-2026-7406 has a CVSS score of 7.8, High severity, and can allow arbitrary code execution through a crafted BMP file. CVE-2026-8325 has a CVSS score of 7.8, High severity, and can cause code execution, data corruption, or a crash through a malicious PDF.

The Revit security update addresses these unsafe file-processing paths and reduces the risk from malicious PDF and BMP content.

Key Details

Affected Product
Autodesk Advance Steel
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-822
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.