CVE-2026-85217
8.6Autodesk · Fusion
Autodesk Fusion contains a vulnerability where a malicious add-in can silently modify persistent network proxy settings, potentially enabling traffic interception and sensitive information exposure.
Executive summary
A high-severity vulnerability in Autodesk Fusion allows a malicious add-in to hijack network traffic by modifying system proxy settings, posing a significant risk to data confidentiality and integrity.
Vulnerability
The application is susceptible to improper control of system configuration settings (CWE-15), where a malicious add-in can modify persistent network proxy settings without user consent. This vector requires a local user to install and execute the crafted add-in, but it does not require prior authentication to the application itself.
Business impact
Successful exploitation permits an attacker to redirect network traffic through a controlled proxy, leading to the potential theft of sensitive design data, credentials, or proprietary intellectual property. With a CVSS score of 8.6, this flaw represents a high risk to business operations, as it facilitates man-in-the-middle attacks that can bypass standard perimeter security controls.
Remediation
Immediate Action: Update Autodesk Fusion to version 2705.1.11 or later immediately to incorporate the necessary configuration protections.
Proactive Monitoring: Monitor endpoint logs for unauthorized modifications to network proxy settings and inspect installed add-ins for suspicious behavior or unsigned components.
Compensating Controls: Enforce strict application control policies that restrict the installation of third-party add-ins and employ network-level monitoring to detect anomalous traffic patterns originating from Fusion clients.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The risk posed by CVE-2026-85217 is significant due to the potential for total compromise of network traffic integrity. Administrators should prioritize the deployment of the vendor-supplied patch and audit existing add-in installations to ensure no unauthorized code is currently present. Failure to remediate this vulnerability may leave sensitive intellectual property exposed to sophisticated interception attacks.
More Autodesk CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section