Junglewise Threat Intelligence

CVE-2026-21300: Adobe Substance3D Modeler NULL pointer dereference

CVE-2026-21300 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Adobe Substance3D Modeler, Adobe Substance 3d Modeler. Vendors: Adobe.

Executive brief

Substance3D Modeler is Adobe's 3D modeling application used by designers and artists to create digital content. A flaw in the application allows it to crash when a user opens a specially crafted malicious file, disrupting work and availability. The vulnerability requires a user to be tricked into opening a malicious file, and poses a denial-of-service risk rather than a path to compromise.

Technical details

A NULL pointer dereference vulnerability exists in Substance3D Modeler versions 1.22.4 and earlier. The vulnerability is triggered when the application attempts to process malformed or specially crafted file input without proper validation, dereferencing a null pointer and causing the application to crash. Exploitation requires user interaction—a victim must open a malicious file—and does not require network access or elevated privileges. An attacker can achieve denial-of-service by preventing the target user from using the application, though the impact is limited to application availability on the affected machine.

Affected products

  • Adobe Substance3D Modeler 1.22.4 and earlier

Timeline

  • 2026-01-13: disclosed

References

Related threats