Executive brief
Substance3D Modeler is Adobe's 3D design and modeling tool used by creative professionals. A memory-reading vulnerability in versions 1.22.5 and earlier could allow an attacker to extract sensitive information from an application's memory if a user opens a malicious file, potentially exposing credentials, design data, or other confidential information.
Technical details
The vulnerability is an out-of-bounds read in Substance3D Modeler versions 1.22.5 and earlier that allows attackers to read data beyond allocated memory boundaries. The attack requires user interaction—specifically, a victim must open a malicious file—but does not require authentication or special privileges. Successful exploitation could disclose sensitive information stored in the application's memory. Adobe has assigned CVE-2026-21348 with a CVSS v3.1 score of 5.5 (medium severity). A patch is likely available from Adobe's security advisory APSB26-22.
Affected products
- Adobe Substance3D Modeler 1.22.5 and earlier
Timeline
- 2026-02-10: disclosed