CVE-2026-1288

A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*

History

29 Jun 2026, 20:03

Type Values Removed Values Added
First Time Autodesk
Autodesk revit
CPE cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
References () https://www.autodesk.com/products/autodesk-access/overview - () https://www.autodesk.com/products/autodesk-access/overview - Product
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0007 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0007 - Vendor Advisory

17 Jun 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 17:16

Updated : 2026-06-29 20:03


NVD link : CVE-2026-1288

Mitre link : CVE-2026-1288

CVE.ORG link : CVE-2026-1288


JSON object : View

Products Affected

autodesk

  • revit
CWE
CWE-476

NULL Pointer Dereference