CVE-2026-14255: Autodesk Shared Components
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially crafted IFC file.
Affected products
- Autodesk Shared Components: from 1.11.0, before 1.12.0 (fixed in 1.12.0); from 2.0.0, before 2.2.0 (fixed in 2.2.0)
Published 2026-09-02. Last modified 2026-09-03.