CVE-2026-0659: USD File Parsing Out-of-Bounds Write Vulnerability
A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0659?
CVE-2026-0659 is classified as a critical severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2026-0659?
To fix CVE-2026-0659, update Autodesk Arnold and Autodesk 3ds Max to the latest versions provided by Autodesk.
What types of software are affected by CVE-2026-0659?
CVE-2026-0659 affects Autodesk Arnold and Autodesk 3ds Max.
What is the nature of the vulnerability in CVE-2026-0659?
CVE-2026-0659 is an Out-of-Bounds Write vulnerability that can be triggered by a malicious USD file.
How can an attacker exploit CVE-2026-0659?
An attacker can exploit CVE-2026-0659 by crafting a malicious USD file that, when loaded, executes arbitrary code in the context of the application.