Out-of-Bounds Write Vulnerability in Substance3D Sampler by Adobe
CVE-2026-21306
7.8HIGH
What is CVE-2026-21306?
The Substance3D Sampler software, developed by Adobe, is vulnerable to an out-of-bounds write flaw present in versions 5.1.0 and earlier. This vulnerability allows for arbitrary code execution within the current user's context, posing a significant risk if exploited. To trigger the vulnerability, user interaction is necessary, as a victim must open a specially crafted malicious file. Users of the affected versions are advised to follow security best practices and stay informed about patches and updates provided by Adobe.
Affected Version(s)
Substance3D - Sampler 0 <= 5.1.0