CVE-2026-1288

A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-17 17:16

Updated : 2026-06-29 20:03


NVD link : CVE-2026-1288

Mitre link : CVE-2026-1288

CVE.ORG link : CVE-2026-1288


JSON object : View

Products Affected

autodesk

  • revit
CWE
CWE-476

NULL Pointer Dereference