CVE-2026-10709 PUBLISHED

FBX BinaryReadSectionHeader Stack-Based Buffer Overflow Vulnerability in Autodesk FBX SDK

Assigner: autodesk
Reserved: 02.06.2026 Published: 04.08.2026 Updated: 04.08.2026

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor Autodesk
Product FBX SDK
Versions Default: unaffected
  • affected from 2020.3.9 to 2020.3.10 (excl.)

References

Problem Types

  • CWE-121 Stack-based Buffer Overflow CWE

Impacts

  • CAPEC-100 Overflow Buffers