Junglewise Threat Intelligence

CVE-2026-21337: Adobe Substance3D Designer out-of-bounds read in file parsing

CVE-2026-21337 · Severity: medium · CVSS 5.5 · Published 2026-02-10

Technologies: Adobe Substance 3d Designer, Adobe Substance3D Designer. Vendors: Adobe.

Executive brief

Adobe Substance3D Designer is a 3D design application used by artists and designers to create digital assets. Versions 15.1.0 and earlier contain a memory reading vulnerability that could expose sensitive data when a user opens a specially crafted malicious file. An attacker could potentially access confidential information stored in application memory, but successful exploitation requires user interaction (opening a file).

Technical details

The vulnerability is an out-of-bounds read (CWE-125) in Substance3D Designer's file parsing logic. The flaw allows an attacker to read arbitrary memory locations by crafting a malicious file that triggers out-of-bounds access during parsing. The attack requires user interaction, as a victim must open the malicious file within the application. This could lead to exposure of sensitive data stored in memory, including but not limited to project data, credentials, or other sensitive information. The issue affects versions 15.1.0 and earlier, and patches are expected to be available from Adobe.

Affected products

  • Adobe Substance3D Designer 15.1.0 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats