CVE-2026-1289: PDF File Parsing Use-After-Free Vulnerability in Autodesk Revit
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1289?
The severity of CVE-2026-1289 is high, with a CVSS score of 7.8.
How does CVE-2026-1289 affect Autodesk Revit?
CVE-2026-1289 affects Autodesk Revit by allowing a Use-After-Free vulnerability that can be exploited through maliciously crafted PDF files.
What can an attacker achieve by exploiting CVE-2026-1289?
An attacker can exploit CVE-2026-1289 to cause application crashes, disclose sensitive data, or execute arbitrary code in the context of the current process.
How can I mitigate the risks associated with CVE-2026-1289?
To mitigate the risks of CVE-2026-1289, users should update Autodesk Revit to the latest version that addresses the vulnerability.
When was CVE-2026-1289 published?
CVE-2026-1289 was published on August 6, 2026.