Junglewise Threat Intelligence

CVE-2026-21334: Adobe Substance3D Designer out-of-bounds write

CVE-2026-21334 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Adobe Substance 3d Designer, Adobe Substance3D Designer. Vendors: Adobe.

Executive brief

Adobe Substance3D Designer is a 3D design tool used by professionals to create digital assets. Versions 15.1.0 and earlier contain an out-of-bounds memory write flaw that could allow arbitrary code execution when a user opens a specially crafted malicious file, potentially compromising the user's system and any projects or data accessible through the application.

Technical details

The vulnerability is a classic out-of-bounds write condition in Substance3D Designer version 15.1.0 and earlier, allowing an attacker to write data beyond allocated memory boundaries. The attack requires user interaction—specifically, the victim must be tricked into opening a malicious file (likely a specially crafted design or project file). Successful exploitation results in arbitrary code execution with the privileges of the current user, potentially enabling full system compromise. No patch availability status is indicated in the advisory; users should check Adobe's security bulletins for remediation guidance.

Affected products

  • Adobe Substance3D Designer 15.1.0 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats