CVE-2026-14478: Autodesk Installer

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.

Affected products

  • Autodesk Installer: before 2.23 (fixed in 2.23)

Published 2026-08-12. Last modified 2026-09-04.