Junglewise Threat Intelligence

CVE-2026-21299: Adobe Substance3D Modeler out-of-bounds write in file handling

CVE-2026-21299 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Adobe Substance3D Modeler, Adobe Substance 3d Modeler. Vendors: Adobe.

Executive brief

Substance3D Modeler is Adobe's 3D modeling application used by designers and artists. A vulnerability allows attackers to execute arbitrary code on a user's system if they trick a user into opening a specially crafted malicious file, potentially compromising the designer's workstation and any projects or credentials stored on it.

Technical details

Substance3D Modeler versions 1.22.4 and earlier contain an out-of-bounds write vulnerability in file handling code. The vulnerability is triggered when a victim opens a malicious file, causing memory corruption that can be leveraged for arbitrary code execution with the privileges of the current user. The attack requires user interaction (opening a file) and succeeds in the context of the logged-in user. A patch is available in versions after 1.22.4.

Affected products

  • Adobe Substance3D Modeler 1.22.4 and earlier

Timeline

  • 2026-01-13: disclosed

References

Related threats