CVE-2026-11803

Summary

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

Affected Software

VendorProductVersion RangeStatus
AutodeskRevit2027.0.0 < 2027.2.0affected
AutodeskRevit2026.0.0 < 2026.5.0affected
AutodeskAutoCAD2027.0.0 < 2027.1.0affected
AutodeskAutoCAD2026.0.0 < 2026.1.2affected
AutodeskAutoCAD2025.0.0 < 2025.1.4affected
AutodeskAutoCAD2024.0.0 < 2024.1.9affected
AutodeskAutoCAD LT2027.0.0 < 2027.1.0affected
AutodeskAutoCAD LT2026.0.0 < 2026.1.2affected
AutodeskAutoCAD LT2025.0.0 < 2025.1.4affected
AutodeskAutoCAD LT2024.0.0 < 2024.1.9affected

Weaknesses

  • CWE-125: CWE-125 Out-of-Bounds Read

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References