Junglewise Threat Intelligence

CVE-2026-21341: Adobe Substance3D Stager out-of-bounds write

CVE-2026-21341 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Adobe Substance 3d Stager, Apple macOS, Microsoft Windows, Adobe Substance3D Stager. Vendors: Adobe, Apple, Microsoft.

Executive brief

Substance3D Stager is Adobe's 3D asset management and staging tool used by designers and artists. Versions 3.1.6 and earlier contain an out-of-bounds write vulnerability that allows attackers to execute arbitrary code with the privileges of the current user. An attacker can exploit this by crafting a malicious file that, when opened by a victim, executes code on their system.

Technical details

The vulnerability is an out-of-bounds write flaw in Substance3D Stager versions 3.1.6 and earlier. The vulnerable component improperly handles file input, allowing an attacker to write beyond the bounds of an allocated memory buffer. This can result in arbitrary code execution within the security context of the current user. The attack requires user interaction—a victim must explicitly open a specially crafted malicious file. There is no indication that this vulnerability has been exploited in the wild as of the advisory date.

Affected products

  • Adobe Substance3D Stager 3.1.6 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats