Junglewise Threat Intelligence

CVE-2026-21363: Adobe Substance3D Painter NULL pointer dereference

CVE-2026-21363 · Severity: medium · CVSS 5.5 · Published 2026-03-10

Technologies: Adobe Substance3D Painter, Adobe Substance 3d Painter. Vendors: Adobe.

Executive brief

Substance3D Painter is a digital painting and texturing tool used by creative professionals to develop 3D assets. Versions 11.1.2 and earlier contain a NULL pointer dereference flaw that causes the application to crash when opening a specially crafted file. An attacker could exploit this to disrupt an artist's work or production pipeline, resulting in lost productivity and project delays.

Technical details

The vulnerability is a NULL pointer dereference in Substance3D Painter versions 11.1.2 and earlier. The flaw can be triggered by processing a malicious file, which causes the application to attempt to access memory through an invalid pointer, resulting in a denial-of-service condition (application crash). Exploitation requires user interaction—a victim must open the malicious file in the application. The vulnerability does not allow remote code execution or data theft, only application termination. Adobe has released patches to address this issue.

Affected products

  • Adobe Substance3D Painter 11.1.2 and earlier

Timeline

  • 2026-03-10: disclosed

References

Related threats