CVE-2026-4369: Stored Cross-Site Scripting (XSS) Vulnerability in Assembly Variant Name
A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4369?
CVE-2026-4369 is classified as a medium severity stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2026-4369?
To mitigate CVE-2026-4369, ensure that you are using the latest version of Autodesk Fusion 360 with security updates applied.
What is the impact of CVE-2026-4369?
CVE-2026-4369 can allow attackers to execute malicious scripts in the context of the user's session.
Which software is affected by CVE-2026-4369?
CVE-2026-4369 affects Autodesk Fusion 360 software specifically.
How is CVE-2026-4369 exploited?
CVE-2026-4369 can be exploited by inserting a malicious HTML payload in an assembly variant name that gets triggered during a delete confirmation dialog.