Security Advisory

CVE-2026-0659

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-02-04 16:01:27
Last updated 2026-02-26 15:04:20
Assigner autodesk
State PUBLISHED

Description

A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.