PT-2026-4203 · Autodesk · Autodesk Fusion

Published

2026-01-22

·

Updated

2026-01-22

·

CVE-2026-0535

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Autodesk Fusion desktop application (affected versions not specified)
Description A specially designed HTML payload, placed within a component's description and activated by a user, can lead to a Stored Cross-site Scripting (XSS) issue. An attacker could potentially use this to access local files or run code with the privileges of the current process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-01816
CVE-2026-0535

Affected Products

Autodesk Fusion