Junglewise Threat Intelligence

CVE-2026-21348: Adobe Substance3D Modeler out-of-bounds read

CVE-2026-21348 · Severity: medium · CVSS 5.5 · Published 2026-02-10

Technologies: Adobe Substance3D Modeler, Adobe Substance 3d Modeler. Vendors: Adobe.

Executive brief

Substance3D Modeler is Adobe's 3D design and modeling tool used by creative professionals. A memory-reading vulnerability in versions 1.22.5 and earlier could allow an attacker to extract sensitive information from an application's memory if a user opens a malicious file, potentially exposing credentials, design data, or other confidential information.

Technical details

The vulnerability is an out-of-bounds read in Substance3D Modeler versions 1.22.5 and earlier that allows attackers to read data beyond allocated memory boundaries. The attack requires user interaction—specifically, a victim must open a malicious file—but does not require authentication or special privileges. Successful exploitation could disclose sensitive information stored in the application's memory. Adobe has assigned CVE-2026-21348 with a CVSS v3.1 score of 5.5 (medium severity). A patch is likely available from Adobe's security advisory APSB26-22.

Affected products

  • Adobe Substance3D Modeler 1.22.5 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats