Junglewise Threat Intelligence

CVE-2026-34681: Adobe Substance 3D Designer out-of-bounds write

CVE-2026-34681 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Adobe Substance 3d Designer. Vendors: Adobe.

Executive brief

Adobe Substance 3D Designer, a professional tool for creating 3D materials and textures, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized access to data or the installation of malicious software on the victim's system.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Substance 3D Designer versions 15.1.0 and earlier. The flaw occurs when the application processes a specially crafted file, leading to memory corruption. An attacker can exploit this by convincing a victim to open a malicious project or asset file. Successful exploitation allows for arbitrary code execution in the context of the current user. Adobe has addressed this issue in newer versions, and users are advised to update to the latest release.

Affected products

  • Adobe Substance 3D Designer 15.1.0 and earlier

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Adobe
  • 2026-05-12: advisory: Adobe security bulletin APSB26-52 published

References

Related threats