Out-of-Bounds Write Vulnerability in Substance3D Painter by Adobe
CVE-2026-21305
7.8HIGH
What is CVE-2026-21305?
Substance3D Painter versions 11.0.3 and earlier are susceptible to an out-of-bounds write vulnerability which may enable arbitrary code execution in the context of the current user. This flaw necessitates user interaction, as it occurs when a malicious file is opened by the user, potentially leading to unauthorized operations on the user's system.
Affected Version(s)
Substance3D - Painter 0 <= 11.0.3