Junglewise Threat Intelligence

CVE-2026-21339: Adobe Substance3D Designer out-of-bounds read in file parsing

CVE-2026-21339 · Severity: medium · CVSS 5.5 · Published 2026-02-10

Technologies: Adobe Substance 3d Designer, Adobe Substance3D Designer. Vendors: Adobe.

Executive brief

Substance3D Designer is a professional 3D content creation tool used by designers and artists. Versions 15.1.0 and earlier contain a memory read vulnerability that could expose sensitive data when a user opens a malicious file. An attacker could exploit this to steal design data, credentials, or other confidential information stored in memory.

Technical details

The vulnerability is an out-of-bounds read that occurs during file parsing in Substance3D Designer versions 15.1.0 and earlier. The root cause appears to be improper bounds checking when reading from memory during file processing. Exploitation requires user interaction—specifically, a victim must open a specially crafted malicious file. The attack vector is local (user must interact with the application). Successful exploitation allows an attacker to read arbitrary memory content, potentially disclosing sensitive information such as design files, API keys, or other confidential data held in the application's memory. Adobe has issued a security advisory addressing this issue.

Affected products

  • Adobe Substance3D Designer 15.1.0 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats