Junglewise Threat Intelligence

CVE-2026-21307: Adobe Substance3D Designer out-of-bounds write

CVE-2026-21307 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Adobe Substance 3d Designer, Adobe Substance3D Designer. Vendors: Adobe.

Executive brief

Substance3D Designer is Adobe's professional 3D design and texturing software used by artists and designers. A flaw in versions 15.0.3 and earlier allows attackers to execute arbitrary code on a user's computer by crafting a malicious file that, when opened, triggers an out-of-bounds memory write. An attacker would need to trick a user into opening a malicious file, potentially compromising the system and any work stored on it.

Technical details

The vulnerability is an out-of-bounds write flaw in Substance3D Designer versions 15.0.3 and earlier. The root cause appears to be improper bounds checking during file parsing or processing. Attack vector is local and requires user interaction: a victim must explicitly open a specially crafted malicious file. Successful exploitation allows arbitrary code execution in the context of the current user. The flaw affects versions up to and including 15.0.3; patch status for newer versions is implied but details are not available in the advisory.

Affected products

  • Adobe Substance3D Designer 15.0.3 and earlier

Timeline

  • 2026-01-13: disclosed

References

Related threats