Junglewise Threat Intelligence

CVE-2026-21365: Adobe Substance3D Painter out-of-bounds read in memory

CVE-2026-21365 · Severity: medium · CVSS 5.5 · Published 2026-03-10

Technologies: Adobe Substance 3d Painter, Adobe Substance3D Painter. Vendors: Adobe.

Executive brief

Substance3D Painter is a professional 3D texture painting application used by digital artists and game developers. Versions 11.1.2 and earlier contain a memory reading flaw that allows attackers to extract sensitive data from memory when a victim opens a crafted file, potentially exposing project data, API keys, or system information.

Technical details

The vulnerability is an out-of-bounds read in Substance3D Painter versions 11.1.2 and earlier. The root cause is improper bounds checking when processing file data, allowing access to memory regions outside allocated buffers. Exploitation requires user interaction—a victim must open a malicious file—making it unlikely to be exploited remotely without social engineering. A successful exploit enables an attacker to read arbitrary memory contents, potentially extracting sensitive information such as credentials, session tokens, or project data. Patched versions are expected in Adobe's security update APSB26-25 or later.

Affected products

  • Adobe Substance3D Painter 11.1.2 and earlier

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: advisory: APSB26-25

References

Related threats