CVE-2026-1288: RFA File Parsing Vulnerability in Autodesk Revit
A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Do not use the 'Convert RFA to FormIt' function on untrusted RFA files; if product or IT controls permit, disable or restrict access to this conversion feature to prevent triggering the NULL pointer dereference.
Autodesk Revit Convert RFA to FormIt = disable / avoid use - Compensating control
Avoid opening or converting RFA files from untrusted sources. Restrict intake of RFA files to trusted sources and treat RFA conversions as high-risk until an official fix is available to prevent application crashes (denial-of-service).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1288?
The severity of CVE-2026-1288 is medium with a CVSS score of 5.5.
How do I fix CVE-2026-1288?
To fix CVE-2026-1288, ensure you update Autodesk Revit to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-1288?
CVE-2026-1288 is a null pointer dereference vulnerability affecting RFA file processing.
What can happen if CVE-2026-1288 is exploited?
Exploitation of CVE-2026-1288 can cause the application to crash, resulting in a denial-of-service condition.
Which software is affected by CVE-2026-1288?
CVE-2026-1288 affects Autodesk Revit when processing specially crafted RFA files.