---
id: CVE-2026-8325
title: >-
  A maliciously crafted PDF file, when parsed through certain Autodesk products,
  can force a Out-of-Bounds Write vulnerability
summary: >-
  A maliciously crafted PDF file, when parsed through certain Autodesk products,
  can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage
  this vulnerability to cause a crash, cause data corruption, or execute
  arbitrary…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: autodesk
product: revit
affected:
  - 'revit >= 2024, < 2024.3.6'
  - 'revit >= 2025, < 2025.4.6'
  - 'revit >= 2026, < 2026.5'
  - 'revit >= 2027, < 2027.2'
patched:
  - revit 2027.2
published: '2026-08-06'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T14:17:52.297'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8325'
references:
  - url: 'https://www.autodesk.com/products/autodesk-access/overview'
    label: psirt@autodesk.com
  - url: 'https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0011'
    label: psirt@autodesk.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-07T00:00:00+00:00'
epss: 0.00131
epssPercentile: 0.03103
ingestedAt: '2026-08-09T02:32:00.142Z'
---

## Overview

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

## Affected

- `revit >= 2024, < 2024.3.6`
- `revit >= 2025, < 2025.4.6`
- `revit >= 2026, < 2026.5`
- `revit >= 2027, < 2027.2`

## Remediation

Upgrade past the affected range:

- `revit 2027.2`
