CVE-2026-14478: Incorrect Permission Assignment in Autodesk Installer Named Pipes
Published Aug 12, 2026
·Updated
A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.
Affected Software
2 affected components
Autodesk Autodesk Installer Named Pipes
Autodesk Installer<2.23
Event History
Aug 12, 2026
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-14478?
CVE-2026-14478 has a high severity rating of 7.8.
2
What type of vulnerability is CVE-2026-14478?
CVE-2026-14478 involves incorrect permission assignment in Autodesk Installer named pipes.
3
How can CVE-2026-14478 be exploited?
CVE-2026-14478 can be exploited by a low-privileged attacker executing a crafted executable to inject IPC messages.
4
What impact can CVE-2026-14478 have on systems?
CVE-2026-14478 can potentially affect the confidentiality, integrity, and availability of a system.
5
How do I mitigate CVE-2026-14478?
To mitigate CVE-2026-14478, ensure that the Autodesk Installer has the latest security updates applied.