Executive brief
Adobe Substance 3D Designer, a professional tool for creating 3D materials and textures, is affected by a security flaw that could allow unauthorized access to files on a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could read sensitive information and files that should normally be restricted, potentially compromising private data or intellectual property.
Technical details
A path traversal vulnerability (CWE-22) exists in Adobe Substance 3D Designer versions 15.1.0 and earlier. The issue stems from improper limitation of pathnames to restricted directories, allowing an attacker to bypass intended access controls. Exploitation requires local access and user interaction, specifically requiring a victim to open a maliciously crafted file. A successful exploit enables the attacker to read arbitrary files from the local file system with the privileges of the application. Adobe has addressed this in newer versions, and the vulnerability is tracked under APSB26-52.
Affected products
- Adobe Substance 3D Designer 15.1.0 and earlier
Timeline
- 2026-05-12: advisory: Initial advisory published by Adobe
- 2026-05-12: disclosed