CVE-2026-0662Untrusted Search Path in 3DS MAX

Severity
7.8HIGHNVD
EPSS
0.0%
top 99.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 4

Description

A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5autodesk/3ds_max20262026.3.2
NVDautodesk/3ds_max20262026.3.2

🔴Vulnerability Details

2
CVEList
Untrusted Search Path Vulnerability when opening max Files2026-02-04
GHSA
GHSA-j98v-582h-h35h: A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the2026-02-04

🕵️Threat Intelligence

1
Wiz
CVE-2026-0662 Impact, Exploitability, and Mitigation Steps | Wiz