KeyShot Vulnerability Could Allow Remote Code Execution (CVE-2026-92202)
A security vulnerability in Luxion KeyShot could allow attackers to execute arbitrary code on a vulnerable computer by exploiting the way the application processes BIP files.
Tracked as CVE-2026-92202, the vulnerability was publicly disclosed by Trend Micro’s Zero Day Initiative (ZDI) on 23 September 2026. ZDI has assigned the flaw a CVSS score of 7.8, placing it in the High severity category.
What is KeyShot?
KeyShot is a professional 3D rendering and visualisation application developed by Luxion. It is used by designers, engineers and other professionals to create photorealistic images and animations from 3D models.
The software supports a range of file formats, including its own BIP project format, which can contain scene and rendering information.
As with many applications that process complex file formats, vulnerabilities in file parsing can potentially provide attackers with a way to execute malicious code.
What is CVE-2026-92202?
CVE-2026-92202 is described by ZDI as an uncontrolled search path element vulnerability in KeyShot’s BIP file parsing functionality.
The problem occurs when KeyShot processes a specially crafted BIP file. According to ZDI, the application can attempt to load a library from an unsecured location.
An attacker could exploit this behaviour by supplying a specially crafted file to a victim. If the victim opens the malicious BIP file using a vulnerable version of KeyShot, malicious code could potentially be executed in the context of the KeyShot process.
The vulnerability is associated with the loading of libraries from an unsafe location, making it possible for an attacker to influence which library is loaded during processing of the malicious file.
User interaction is required
CVE-2026-92202 is not described as a vulnerability that can simply be exploited against a KeyShot installation without any involvement from the user.
The ZDI advisory states that user interaction is required. An attacker would need to persuade the target to visit a malicious page or open a malicious file.
In a realistic attack, this could involve sending a malicious KeyShot project to a designer or engineer, placing a file on a shared location, or otherwise convincing someone to open an untrusted BIP file.
Once the file is opened, exploitation could potentially allow arbitrary code to execute with the privileges available to the KeyShot process.
CVSS score of 7.8
ZDI has assigned CVE-2026-92202 a CVSS v3 score of 7.8.
The published vector is:
CVSS:3.1/AV/AC/PR/UI/S/C/I/A
The score reflects several important characteristics of the vulnerability. The attack requires local interaction with the vulnerable application and user interaction, but successful exploitation could have a significant impact on confidentiality, integrity and availability.
Although ZDI describes the vulnerability as allowing remote attackers to execute code, the CVSS vector classifies the attack as requiring local access because the malicious file must ultimately be processed by the vulnerable KeyShot installation.
No known exploitation in the wild
At the time of writing, there is no indication in the available vulnerability information that CVE-2026-92202 is being actively exploited in the wild.
The available tracking information also shows that the vulnerability has not been listed in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue.
However, the absence of known exploitation does not mean the vulnerability should be ignored. Public disclosure gives attackers information about the affected component and the conditions required for exploitation.
Luxion has released an update
Luxion has issued an update to address the vulnerability.
ZDI’s advisory directs users to Luxion’s security advisory for the corrective update and recommends applying the vendor-provided fix.
Organisations using KeyShot should therefore check the versions installed across workstations and update affected installations rather than relying solely on users to avoid suspicious files.
Why BIP files are important
BIP files are used by KeyShot to store project and scene information. Because these files are designed to be opened by the application, they can provide an attractive delivery mechanism for an attacker.
A malicious file could potentially be disguised as a legitimate project, design or rendering file. In an organisation where designers regularly exchange KeyShot projects, distinguishing between a legitimate file and a deliberately crafted malicious one may not always be straightforward.
This makes software updates particularly important for systems used to open files received from customers, suppliers, contractors or other external sources.
What should KeyShot users do?
Users and organisations running KeyShot should:
- Install Luxion’s security update addressing CVE-2026-92202.
- Check that KeyShot installations are running a current supported release.
- Avoid opening BIP files received from unknown or untrusted sources.
- Treat unexpected KeyShot project files received by email or file-sharing services with caution.
- Consider application controls that restrict the execution of untrusted files.
- Monitor security software and endpoint logs for unusual activity following the opening of suspicious KeyShot files.
Organisations should also consider where KeyShot is deployed and whether users routinely receive project files from outside the organisation.
Coordinated disclosure
The vulnerability was reported to Luxion by security researcher Sean de Regge.
According to the ZDI disclosure timeline, the vulnerability was reported to the vendor on 29 April 2026, followed by coordinated public disclosure on 23 September 2026.
The issue was published as ZDI-26-748 and ZDI-CAN-29268 alongside the CVE identifier CVE-2026-92202.
Conclusion
CVE-2026-92202 highlights the security risks associated with applications that process complex 3D project files.
The vulnerability affects KeyShot’s handling of BIP files and could allow arbitrary code execution when a specially crafted file is opened. While exploitation requires user interaction and there is currently no indication that the vulnerability is being exploited in the wild, the potential impact of successful exploitation is significant.
KeyShot users should apply Luxion’s corrective update and exercise caution when opening BIP files received from untrusted sources.

I am one of the editors here at www.systemtek.co.uk I am a UK based technology professional, with an interest in computer security and telecoms.
