CVE-2026-85217
largeMalicious add-in can silently hijack proxy settings in Autodesk Fusion Desktop
CVE-2026-85217 is a flaw in Autodesk Fusion Desktop in which add-ins are permitted to modify the user's persistent network proxy settings without notification or consent, allowing external control of a system-level configuration. Exploitation requires user interaction: a victim must install and run a maliciously crafted add-in, and no elevated privileges are needed. Once the crafted add-in is executed, the attacker can silently redirect Fusion's authenticated network traffic through a proxy under their control, potentially exposing sensitive information handled by the current user; because the proxy change is persistent, it survives across sessions. Anyone running Autodesk Fusion Desktop who installs untrusted add-ins is affected, and the available data does not specify vulnerable version ranges. The flaw is not yet in CISA's KEV, no public proof-of-concept is known, and there are no confirmed reports of in-the-wild exploitation.
What to do: Update Fusion Desktop to a version listed as fixed in Autodesk's PSIRT advisory for CVE-2026-85217 (no fixed version is given in the available data), and in the meantime install add-ins only from trusted sources. On machines where add-ins from unverified sources were installed, audit the persistent system and user proxy settings for unexpected entries, remove any unexplained proxy configuration, and investigate where that proxy may have routed traffic.
| Autodesk Fusion Desktop | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing sensitive information with the current user.
- Weakness
- CWE-15
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.