Arbitrary Proxy Configuration via Autodesk Fusion Desktop Add-ins
CVE-2026-85217 allows a malicious Autodesk Fusion add-in to silently modify network proxy settings, enabling traffic interception and potential sensitive data exfiltration.
CVE search metadata
CVE search record: CVE-2026-85217. Severity: high. CVSS: 8.6. KEV: no. Product: Fusion Desktop. Brief: Arbitrary Proxy Configuration via Autodesk Fusion Desktop Add-ins. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85217/
CVE-2026-85217 is a security vulnerability in Autodesk Fusion Desktop that permits a maliciously crafted add-in to modify persistent network proxy settings without requiring user notification or consent. This vulnerability occurs during the execution of an installed add-in, allowing an attacker to intercept, redirect, or inspect authenticated network traffic generated by the application. Because the proxy modification can be performed silently, an attacker can position themselves as a Man-in-the-Middle (MitM) for Fusion traffic. This facilitates the theft of session tokens, credentials, or proprietary design data transmitted during the user's session. The scope of this threat is significant as it affects the confidentiality of intellectual property managed within the Fusion platform. Defenders should be aware that the primary vector is the installation and execution of untrusted third-party extensions within the Fusion ecosystem.
Impact
Successful exploitation allows for the redirection of authenticated application traffic to an attacker-controlled endpoint. This results in the exposure of sensitive design information and potential credential harvesting for the authenticated user's Autodesk account. The impact is primarily focused on the confidentiality of design data and the integrity of user sessions within the Autodesk Fusion Desktop environment.
Recommendation
Prioritize the implementation of organizational policies that restrict the installation of third-party add-ins for Autodesk Fusion to only those that have been vetted and cryptographically signed by trusted developers. Monitor endpoints for unauthorized modifications to global or application-specific proxy configurations, particularly those occurring in proximity to the execution of Autodesk Fusion or its associated subprocesses. Ensure all Fusion Desktop instances are updated to the latest vendor-supplied version to remediate the underlying lack of validation for proxy modification requests.
Immediate actions
Review and restrict add-in installation policies for Autodesk Fusion across the enterprise.
Mitigations
Identify and remove any unauthorized or untrusted add-ins from Autodesk Fusion Desktop installations.
CVE-2026-85217