CVE-2026-14478: Autodesk Installer
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.
Affected products
- Autodesk Installer: before 2.23 (fixed in 2.23)
Published 2026-08-12. Last modified 2026-09-04.