Vulnerability Details CVE-2026-10789
A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 20.7%
CVSS Severity
CVSS v3 Score 9.6
Products affected by CVE-2026-10789
-
cpe:2.3:a:autodesk:fusion:2.0.20754
-
cpe:2.3:a:autodesk:fusion:2.0.20948
-
cpe:2.3:a:autodesk:fusion:2.0.20962
-
cpe:2.3:a:autodesk:fusion:2.0.20970
-
cpe:2.3:a:autodesk:fusion:2.0.20981
-
cpe:2.3:a:autodesk:fusion:2.0.21286
-
cpe:2.3:a:autodesk:fusion:2.0.21487
-
cpe:2.3:a:autodesk:fusion:2.0.21508
-
cpe:2.3:a:autodesk:fusion:2.0.21528
-
cpe:2.3:a:autodesk:fusion:2.0.21538
-
cpe:2.3:a:autodesk:fusion:2.0.21550
-
cpe:2.3:a:autodesk:fusion:2601.0.90
-
cpe:2.3:a:autodesk:fusion:2601.1.29
-
cpe:2.3:a:autodesk:fusion:2601.1.34
-
cpe:2.3:a:autodesk:fusion:2601.1.37
-
cpe:2.3:a:autodesk:fusion:2602.0.71
-
cpe:2.3:a:autodesk:fusion:2602.1.14
-
cpe:2.3:a:autodesk:fusion:2602.1.25
-
cpe:2.3:a:autodesk:fusion:2603.0.86
-
cpe:2.3:a:autodesk:fusion:2603.1.15
-
cpe:2.3:a:autodesk:fusion:2603.1.31
-
cpe:2.3:a:autodesk:fusion:2603.1.52
-
cpe:2.3:a:autodesk:fusion:2604.1.25
-
cpe:2.3:a:autodesk:fusion:2604.1.48
-
cpe:2.3:a:autodesk:fusion:2605.0.97
-
cpe:2.3:a:autodesk:fusion:2605.1.18
-
cpe:2.3:a:autodesk:fusion:2605.1.39
-
cpe:2.3:a:autodesk:fusion:2605.1.52
-
cpe:2.3:a:autodesk:fusion:2606.1.21
-
cpe:2.3:a:autodesk:fusion:2606.1.22