Junglewise Threat Intelligence

CVE-2026-21308: Adobe Substance3D Designer out-of-bounds read in file parsing

CVE-2026-21308 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Adobe Substance 3d Designer, Adobe Substance3D Designer. Vendors: Adobe.

Executive brief

Substance3D Designer is Adobe's 3D design and texturing application used by artists and designers. Versions 15.0.3 and earlier contain a memory read vulnerability that could expose sensitive data when a user opens a malicious design file. While exploitation requires user interaction, the flaw could lead to disclosure of confidential project data or system information.

Technical details

The vulnerability is an out-of-bounds read in Substance3D Designer's file parsing logic, affecting versions 15.0.3 and earlier. An attacker can craft a malicious design file that triggers the out-of-bounds read when opened by a victim, allowing memory disclosure. The attack requires user interaction (opening the malicious file) and local execution context; the vulnerability does not provide remote code execution or privilege escalation. Adobe has patched this issue in versions later than 15.0.3.

Affected products

  • Adobe Substance3D Designer 15.0.3 and earlier

Timeline

  • 2026-01-13: disclosed

References

Related threats