CVE-2026-14255
Received Received - Intake

Uncontrolled Recursion in Autodesk IFC File Parsing

Vulnerability report for CVE-2026-14255, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Autodesk

Description

A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially crafted IFC file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a maliciously crafted IFC file that, when opened in certain Autodesk products, triggers an Uncontrolled Recursion flaw. This can cause the application to crash unexpectedly, leading to a denial-of-service condition.

Detection Guidance

Detection primarily relies on monitoring Autodesk applications for crashes when opening IFC files. No specific commands are provided in the context. Ensure IFC files are scanned for anomalies before opening.

Impact Analysis

If exploited, this vulnerability could cause the affected Autodesk application to terminate abruptly, disrupting your workflow and potentially leading to data loss or downtime. Users must open a specially crafted file for exploitation to occur.

Mitigation Strategies

Avoid opening untrusted IFC files. Update Autodesk products to the latest patched versions. Implement file validation checks before processing IFC files in your environment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14255. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart