Junglewise Threat Intelligence

CVE-2026-21345: Adobe Substance3D Stager out-of-bounds read in file parsing

CVE-2026-21345 · Severity: high · CVSS 7.8 · Published 2026-02-10

Technologies: Adobe Substance 3d Stager, Apple macOS, Microsoft Windows, Adobe Substance3D Stager. Vendors: Adobe, Apple, Microsoft.

Executive brief

Substance3D Stager is Adobe's 3D asset preparation and staging tool used by designers and artists. A memory read vulnerability in file parsing could allow an attacker to crash the application or execute arbitrary code if a victim opens a specially crafted malicious file.

Technical details

The vulnerability is an out-of-bounds read (CWE-125) occurring when Substance3D Stager parses a crafted file, causing the application to read past the end of an allocated memory structure. The attack vector requires user interaction: a victim must open a malicious file to trigger the vulnerable code path. Successful exploitation could result in code execution in the context of the current user, potentially leading to arbitrary code execution with user privileges. Patches are available in versions after 3.1.6.

Affected products

  • Adobe Substance3D Stager 3.1.6 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats