Junglewise Threat Intelligence

CVE-2026-21303: Adobe Substance3D Modeler out-of-bounds read in file parsing

CVE-2026-21303 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Adobe Substance3D Modeler, Adobe Substance 3d Modeler. Vendors: Adobe.

Executive brief

Substance3D Modeler is Adobe's professional 3D modeling and design tool used by creative professionals. A memory reading vulnerability in versions 1.22.4 and earlier allows an attacker to extract sensitive data from memory by tricking a user into opening a specially crafted file, potentially exposing passwords, keys, or other confidential information.

Technical details

The vulnerability is an out-of-bounds read flaw in Substance3D Modeler's file parsing logic that occurs when processing malicious input files. An attacker can craft a specially formatted file that triggers an out-of-bounds memory access, allowing them to read adjacent memory contents and exfiltrate sensitive data. The attack requires user interaction—a victim must open the malicious file in the application. No patch information is currently available for versions 1.22.4 and earlier.

Affected products

  • Adobe Substance3D Modeler 1.22.4 and earlier

Timeline

  • 2026-01-13: disclosed

References

Related threats