Junglewise Threat Intelligence

CVE-2026-21302: Adobe Substance3D Modeler out-of-bounds read in file parsing

CVE-2026-21302 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Adobe Substance3D Modeler, Adobe Substance 3d Modeler. Vendors: Adobe.

Executive brief

Substance3D Modeler is Adobe's 3D design and modeling tool used by creative professionals. A memory reading flaw in versions 1.22.4 and earlier could allow an attacker to expose sensitive data (passwords, API keys, proprietary designs) if a user opens a specially crafted malicious 3D file. The vulnerability requires explicit user action to trigger and does not allow remote execution or system takeover.

Technical details

An out-of-bounds read vulnerability exists in Substance3D Modeler's file parsing logic, affecting versions 1.22.4 and earlier. The vulnerability is triggered when a user opens a maliciously crafted 3D file that causes the parser to read memory beyond the intended buffer boundaries. This allows an attacker to read and disclose sensitive information resident in the application's memory, such as session tokens, credentials, or other confidential data. Exploitation requires user interaction (opening a malicious file) and network availability is not required. Adobe has issued patches to remediate this issue.

Affected products

  • Adobe Substance3D Modeler 1.22.4 and earlier

Timeline

  • 2026-01-13: disclosed: CVE-2026-21302 published

References

Related threats