CVE-2026-7405 Details
Description
A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service
A vulnerability allowing an out-of-bounds read has been identified in certain Autodesk products, including Autodesk Revit, AutoCAD, Civil 3D, and Advance Steel. This vulnerability arises when a maliciously crafted TIF file is imported, causing an out-of-bounds read in the image handling library. Exploitation of this vulnerability can lead to a denial-of-service condition.
Users are advised to update to the latest versions of the affected products. For Autodesk Revit, versions 2027.1, 2026.5, and 2024.3.5 are available. For Autodesk AutoCAD and its specialized toolsets, version 2027.1 is recommended. These updates can be installed via Autodesk Access or the Accounts Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.autodesk.com/products/autodesk-access/overview | [email protected] | Product |
| https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0012 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| autodesk advance steel | >= 2027, < 2027.1 |
CPE
Remediation
| |
| autodesk autocad | >= 2027, < 2027.1 |
CPE
Remediation
| |
| autodesk autocad architecture | >= 2027, < 2027.1 |
CPE
Remediation
| |
| autodesk autocad electrical | >= 2027, < 2027.1 |
CPE
Remediation
| |
| autodesk autocad lt | >= 2027, < 2027.1 |
CPE
Remediation
| |
| autodesk autocad map 3d | >= 2027, < 2027.1 |
CPE
Remediation
| |
| autodesk autocad mechanical | >= 2027, < 2027.1 |
CPE
Remediation
| |
| autodesk autocad mep | >= 2027, < 2027.1 |
CPE
Remediation
| |
| autodesk autocad plant 3d | >= 2027, < 2027.1 |
CPE
Remediation
| |
| autodesk civil 3d | >= 2027, < 2027.1 |
CPE
Remediation
| |
| autodesk dwg trueview | >= 2027, < 2027.1 |
CPE
Remediation
| |
| autodesk revit | >= 2025, < 2025.3.5 >= 2026, < 2026.5 >= 2027, < 2027.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | [email protected] |
| Sep 4, 2026 | Initial Analysis | [email protected] |
| Sep 2, 2026 | CVE Modified | [email protected] |
| Aug 7, 2026 | CVE Modified | [email protected] |
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |