CVE-2026-85217

8.6

Autodesk · Fusion

Autodesk Fusion contains a vulnerability where a malicious add-in can silently modify persistent network proxy settings, potentially enabling traffic interception and sensitive information exposure.

Executive summary

A high-severity vulnerability in Autodesk Fusion allows a malicious add-in to hijack network traffic by modifying system proxy settings, posing a significant risk to data confidentiality and integrity.

Vulnerability

The application is susceptible to improper control of system configuration settings (CWE-15), where a malicious add-in can modify persistent network proxy settings without user consent. This vector requires a local user to install and execute the crafted add-in, but it does not require prior authentication to the application itself.

Business impact

Successful exploitation permits an attacker to redirect network traffic through a controlled proxy, leading to the potential theft of sensitive design data, credentials, or proprietary intellectual property. With a CVSS score of 8.6, this flaw represents a high risk to business operations, as it facilitates man-in-the-middle attacks that can bypass standard perimeter security controls.

Remediation

Immediate Action: Update Autodesk Fusion to version 2705.1.11 or later immediately to incorporate the necessary configuration protections.

Proactive Monitoring: Monitor endpoint logs for unauthorized modifications to network proxy settings and inspect installed add-ins for suspicious behavior or unsigned components.

Compensating Controls: Enforce strict application control policies that restrict the installation of third-party add-ins and employ network-level monitoring to detect anomalous traffic patterns originating from Fusion clients.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The risk posed by CVE-2026-85217 is significant due to the potential for total compromise of network traffic integrity. Administrators should prioritize the deployment of the vendor-supplied patch and audit existing add-in installations to ensure no unauthorized code is currently present. Failure to remediate this vulnerability may leave sensitive intellectual property exposed to sophisticated interception attacks.

More Autodesk CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources