Out-of-bounds read in Autodesk products - CVE-2026-17550

 

Out-of-bounds read in Autodesk products - CVE-2026-17550

Published: July 29, 2026 / Updated: July 30, 2026


Vulnerability identifier: #VU140568
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-17550
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in the DWG and DXF file parser when parsing a crafted DWG or DXF file. A remote attacker can supply a specially crafted file to disclose sensitive information.

User interaction is required to open or parse the crafted file.


Affected software

Autodesk AutoCAD
AutoCAD Architecture
AutoCAD Electrical
AutoCAD Mechanical
AutoCAD MEP
AutoCAD Plant 3D
Autodesk Civil 3D
Advance Steel
AutoCAD Map 3D
AutoCAD LT
DWG Trueview

How to mitigate CVE-2026-17550

Install security update from vendor's website.

Autodesk AutoCAD - update to 2027.1
AutoCAD Architecture - update to 2027.1
AutoCAD Electrical - update to 2027.1
AutoCAD Mechanical - update to 2027.1
AutoCAD MEP - update to 2027.1
AutoCAD Plant 3D - update to 2027.1
Autodesk Civil 3D - update to 2027.1
Advance Steel - update to 2027.1
AutoCAD Map 3D - update to 2027.1
AutoCAD LT - update to 2027.1
DWG Trueview - update to 2027.1

External References

Related Security Bulletins