Improper access control in Fusion 360 - CVE-2026-10789
Published: June 24, 2026
Fusion 360
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper access control in the MCP extension when processing a maliciously crafted webpage visited by a user while Autodesk Fusion Desktop is running. A remote attacker can cause the user to visit a maliciously crafted webpage to execute arbitrary code.
Exploitation requires the MCP extension to be enabled and user interaction is required.