Out-of-Bounds Write Vulnerability in Substance3D Modeler by Adobe
CVE-2026-21299
7.8HIGH
What is CVE-2026-21299?
Adobe Substance3D Modeler prior to version 1.22.5 is susceptible to an out-of-bounds write vulnerability. Successful exploitation of this flaw could allow an attacker to execute arbitrary code within the context of the user. This typically requires the user to interactively open a specially crafted malicious file, leading to potential unauthorized access and system compromise.
Affected Version(s)
Substance3D - Modeler 0 <= 1.22.4
Substance3D - Modeler 1.22.5