Junglewise Threat Intelligence

CVE-2026-21336: Adobe Substance3D Designer NULL pointer dereference

CVE-2026-21336 · Severity: medium · CVSS 5.5 · Published 2026-02-10

Technologies: Adobe Substance 3d Designer, Adobe Substance3D Designer. Vendors: Adobe.

Executive brief

Substance3D Designer, Adobe's professional 3D design and editing tool, contains a NULL pointer dereference flaw that crashes the application when processing a malicious file. An attacker can exploit this by distributing a crafted file that, when opened by a designer, causes the application to crash and disrupt their work.

Technical details

The vulnerability is a NULL pointer dereference affecting Substance3D Designer versions 15.1.0 and earlier. The flaw is triggered when the application attempts to process a specially crafted file, resulting in a crash that leads to denial of service. Exploitation requires user interaction—specifically, a victim must open a malicious file for the vulnerability to be triggered. The attack vector is local and does not require authentication or elevated privileges beyond the ability to deliver a file to the target.

Affected products

  • Adobe Substance3D Designer 15.1.0 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats