Junglewise Threat Intelligence

CVE-2026-21298: Adobe Substance3D Modeler out-of-bounds write

CVE-2026-21298 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Adobe Substance3D Modeler, Adobe Substance 3d Modeler. Vendors: Adobe.

Executive brief

Substance3D Modeler is Adobe's 3D design tool used by creative professionals to build and model 3D assets. Versions 1.22.4 and earlier contain a memory vulnerability that allows attackers to execute arbitrary code on a user's system if they trick the user into opening a malicious 3D model file. This could lead to complete system compromise, data theft, and loss of control over the affected workstation.

Technical details

The vulnerability is an out-of-bounds write flaw in Substance3D Modeler that enables arbitrary code execution within the context of the current user. The vulnerability requires user interaction—specifically, the victim must open a malicious file—to be exploited. The attack vector is local, requiring the attacker to deliver a crafted file to the target. No network exploitation or elevated privileges are required beyond standard user access. A patch is available for versions 1.22.5 and later.

Affected products

  • Adobe Substance3D Modeler 1.22.4 and earlier

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: patched: Fixed in version 1.22.5 and later

References

Related threats