Junglewise Threat Intelligence

CVE-2026-21305: Adobe Substance3D Painter out-of-bounds write

CVE-2026-21305 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Adobe Substance3D Painter, Adobe Substance 3d Painter. Vendors: Adobe.

Executive brief

Substance3D Painter is a digital painting and texturing tool used by 3D artists and game developers. Versions 11.0.3 and earlier contain a vulnerability that could allow an attacker to run malicious code on a user's computer if they open a specially crafted file. The attack requires the victim to manually open a malicious file, but successful exploitation could lead to complete system compromise.

Technical details

The vulnerability is an out-of-bounds write flaw in Substance3D Painter versions 11.0.3 and earlier. The root cause involves improper bounds checking when processing input files, allowing an attacker to write data beyond allocated memory. The attack vector is local and requires user interaction—specifically, a victim must open a malicious file in the application. Successful exploitation can lead to arbitrary code execution in the context of the current user. There is no indication of active exploitation in the wild as of the advisory date. A patch is expected from Adobe via security bulletin APSB26-10.

Affected products

  • Adobe Substance3D Painter 11.0.3 and earlier

Timeline

  • 2026-01-13: disclosed

References

Related threats