CVE-2026-10789: MCP Extension Code Injection Vulnerability in Autodesk Fusion Desktop
A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the MCP extension in Autodesk Fusion Desktop (turn off the MCP extension so it is not enabled while running Fusion Desktop).
Autodesk Fusion Desktop - MCP extension MCP extension enabled = false
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10789?
CVE-2026-10789 has a critical severity score of 9.6.
How do I fix CVE-2026-10789?
To fix CVE-2026-10789, update to the latest version of Autodesk Fusion Desktop as provided by Autodesk.
What does CVE-2026-10789 allow attackers to do?
CVE-2026-10789 allows attackers to execute arbitrary code with the privileges of the current user.
Which software is affected by CVE-2026-10789?
CVE-2026-10789 affects Autodesk Fusion Desktop when the MCP extension is enabled.
How can this vulnerability be triggered?
CVE-2026-10789 can be triggered by visiting a maliciously crafted webpage while Autodesk Fusion Desktop is running.