Local Code Injection Vulnerability in Autodesk Products
CVE-2026-14478

7.8HIGH

Key Information:

Vendor

Autodesk

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-14478?

A vulnerability exists in certain Autodesk products where a malicious executable can be used to execute unauthorized IPC messages through named pipes. This can lead to alterations in pipe permissions and ownership, compromising the confidentiality, integrity, and availability of the affected systems. Users should be aware of this risk and apply the necessary security measures.

Affected Version(s)

Installer 2.22.0 < 2.23.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.