CVE-2026-85217: Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop
A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing sensitive information with the current user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Detect and block unauthorized changes by enforcing network egress through approved/managed proxies for Autodesk Fusion Desktop to prevent traffic redirection to attacker-controlled proxies.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Autodesk Fusion Desktop users who install and execute a maliciously crafted add-in are exposed. The potential impact applies to authenticated Fusion network traffic associated with the current user.
What conditions are required for exploitation?
The malicious add-in must be installed and executed in Autodesk Fusion Desktop. The attacker can then modify persistent network proxy settings without user notification or consent.
What could an attacker gain by exploiting this?
An attacker may redirect authenticated Fusion network traffic through an attacker-controlled proxy. This could expose sensitive information available to the current user.