Junglewise Threat Intelligence

CVE-2026-21364: Adobe Substance 3D Painter NULL pointer dereference

CVE-2026-21364 · Severity: medium · CVSS 5.5 · Published 2026-03-10

Technologies: Adobe Substance 3d Painter. Vendors: Adobe.

Executive brief

Substance 3D Painter, a professional 3D painting and texturing application, contains a NULL pointer dereference flaw that crashes the application when processing malicious files. An attacker can craft a malicious project or asset file that, when opened by a user, causes the application to crash, disrupting creative workflows and potentially causing loss of unsaved work.

Technical details

The vulnerability is a NULL pointer dereference in Substance 3D Painter versions 11.1.2 and earlier. The flaw occurs when the application processes a malformed or specially crafted file without properly validating pointer references before dereferencing them. Exploitation requires user interaction: a victim must open a malicious file, typically a project or texture asset. A successful exploit results in application crash and denial-of-service, but does not enable code execution or data theft. Adobe has issued security advisory APSB26-25 with patched versions.

Affected products

  • Adobe Substance 3D Painter 11.1.2 and earlier

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: advisory: Adobe security advisory APSB26-25 issued

References

Related threats