Stack-Based Buffer Overflow in Autodesk FBX SDK Affecting Multiple Versions
CVE-2026-10710

7.8HIGH

Key Information:

Vendor

Autodesk

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-10710?

A vulnerability exists in Autodesk's FBX SDK due to improper handling of specially crafted FBX files. When such a file is processed, it can lead to a stack-based buffer overflow in the 'fbxsdk::ExtractDrive' function. This may allow an attacker to execute arbitrary code within the context of the affected application, potentially compromising system integrity and user data. It's crucial for users to update to the latest version of the FBX SDK to mitigate this risk.

Affected Version(s)

FBX SDK 2020.3.9 < 2020.3.10

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.