Arbitrary Code Execution Vulnerability in Autodesk Fusion Desktop MCP Extension
CVE-2026-10789

9.6CRITICAL

Key Information:

Vendor

Autodesk

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-10789?

A security vulnerability exists in the MCP extension of Autodesk Fusion Desktop, which can be exploited when a user visits a specially crafted webpage. This vulnerability may allow an attacker to execute arbitrary code with the privileges of the current user, posing significant security risks. Users are advised to ensure that their software is updated and to exercise caution when accessing unknown web content.

Affected Version(s)

Fusion 2703.1.11 < 2703.1.20

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.