← Back to search

CVE-2026-10709

7.8 HIGH

Published 2026-08-04 · Updated 2026-08-05

AI risk analysis

Summary
This flaw involves a stack-based buffer overflow in the parsing of FBX files using Autodesk's FBX SDK, allowing arbitrary code execution.
Exploitability
Exploitation requires a maliciously crafted FBX file and access to parse it through the affected SDK; this is moderately difficult due to the need for specific input.
Blast radius
If exploited, this vulnerability could lead to full compromise of systems using the affected software, including data theft or system control.
Prioritized remediation
Update to the latest version of Autodesk FBX SDK that addresses this vulnerability.
rcefile-formatsdkautodesk

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-121

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.