Junglewise Threat Intelligence

CVE-2026-21342: Adobe Substance3D Stager out-of-bounds write vulnerability

CVE-2026-21342 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Adobe Substance 3d Stager, Apple macOS, Microsoft Windows, Adobe Substance3D Stager. Vendors: Adobe, Apple, Microsoft.

Executive brief

Adobe Substance3D Stager is a 3D design asset staging tool used by creative professionals. Versions 3.1.6 and earlier contain an out-of-bounds write vulnerability that allows attackers to execute arbitrary code on a user's system when the user opens a specially crafted malicious file. This could enable attackers to compromise creative workstations and steal design assets or intellectual property.

Technical details

The vulnerability is an out-of-bounds write (CWE-787) that occurs in Substance3D Stager versions 3.1.6 and earlier. The flaw allows arbitrary code execution in the context of the current user. Exploitation requires user interaction—specifically, a victim must open a malicious file. The attack vector is local, initiated through file handling. An attacker can achieve arbitrary code execution with the privileges of the user running the application. Adobe has issued patches; users should update to versions later than 3.1.6.

Affected products

  • Adobe Substance3D Stager 3.1.6 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats