7.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Basic Information
ID
CVE-2026-0659
Source
autodesk
Published
Feb 4, 2026 at 16:01
Modified
Feb 4, 2026 at 16:39
Affected Product
Vendor
Autodesk
Product
USD for Arnold
Version
7.4.4.1
Affected Versions
Autodesk USD for Arnold 7.4.4.1
Autodesk Arnold 7.4.4.1
Autodesk 3ds Max 2026.2
Autodesk Arnold 7.4.4.1
Autodesk 3ds Max 2026.2