CVE-2026-1288
EUVD-2026-3774417.06.2026, 17:16
A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| autodesk | revit | 2024 ≤ 𝑥 < 2024.3.5 |
| autodesk | revit | 2025 ≤ 𝑥 < 2025.4.5 |
| autodesk | revit | 2026 ≤ 𝑥 < 2026.4.1 |
| autodesk | revit | 2027 ≤ 𝑥 < 2027.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration