Junglewise Threat Intelligence

CVE-2026-21343: Adobe Substance3D Stager out-of-bounds read in file parsing

CVE-2026-21343 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Adobe Substance 3d Stager, Apple macOS, Microsoft Windows, Adobe Substance3D Stager. Vendors: Adobe, Apple, Microsoft.

Executive brief

Substance3D Stager is a 3D asset preparation tool used by designers and creative professionals. A flaw in how it processes crafted files allows reading past the end of allocated memory, potentially enabling attackers to execute arbitrary code on a user's system when they open a malicious file. The attack requires user interaction but poses a significant risk to creative workflows and systems handling sensitive design assets.

Technical details

The vulnerability is an out-of-bounds read (CWE-125) in Substance3D Stager's file parsing functionality that permits reading past the end of an allocated memory structure. The root cause lies in insufficient bounds checking when processing crafted input files. The attack vector is local with user interaction required—a victim must open a malicious file. Successful exploitation allows code execution in the context of the current user. The vulnerability affects versions 3.1.6 and earlier; patched versions should be available from Adobe.

Affected products

  • Adobe Substance3D Stager 3.1.6 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats