Out-of-Bounds Write Vulnerability in Substance3D Sampler by Adobe
CVE-2026-21306

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
13 January 2026

What is CVE-2026-21306?

The Substance3D Sampler software, developed by Adobe, is vulnerable to an out-of-bounds write flaw present in versions 5.1.0 and earlier. This vulnerability allows for arbitrary code execution within the current user's context, posing a significant risk if exploited. To trigger the vulnerability, user interaction is necessary, as a victim must open a specially crafted malicious file. Users of the affected versions are advised to follow security best practices and stay informed about patches and updates provided by Adobe.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Substance3D - Sampler 0 <= 5.1.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.