Unauthorized Proxy Modification via Malicious Addin in Autodesk Fusion Desktop
CVE-2026-85217 Published on September 10, 2026
Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop
A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing sensitive information with the current user.
Vulnerability Analysis
CVE-2026-85217 can be exploited with local system access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
External Control of System or Configuration Setting
One or more system settings or configuration elements can be externally controlled by a user. Allowing external control of system settings can disrupt service or cause an application to behave in unexpected, and potentially malicious ways.
Products Associated with CVE-2026-85217
Want to know whenever a new CVE is published for AutoDesk Fusion? stack.watch will email you.
Affected Versions
Autodesk Fusion:- Version 2705.0.0 and below 2705.1.11 is affected.