Junglewise Threat Intelligence

CVE-2026-21301: Adobe Substance3D Modeler NULL pointer dereference

CVE-2026-21301 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Adobe Substance3D Modeler, Adobe Substance 3d Modeler. Vendors: Adobe.

Executive brief

Substance3D Modeler is Adobe's 3D design and modeling application used by creative professionals. A NULL pointer dereference flaw in versions 1.22.4 and earlier can crash the application when a user opens a specially crafted malicious file, causing temporary loss of work and disruption to design workflows.

Technical details

The vulnerability is a NULL pointer dereference in Substance3D Modeler version 1.22.4 and earlier. The flaw is triggered when processing a malicious file, leading to application denial-of-service (crash). Exploitation requires user interaction—specifically, a victim must open a crafted file, likely via email, file sharing, or a compromised source. The attacker cannot gain code execution or access sensitive data, but can disrupt availability and potentially cause loss of unsaved work. A patch is expected to be available through Adobe's security advisory.

Affected products

  • Adobe Substance3D Modeler 1.22.4 and earlier

Timeline

  • 2026-01-13: disclosed: Published on NVD
  • 2026-01-13: advisory: Adobe APSB26-08 advisory

References

Related threats