Path Traversal Vulnerability in Adobe Substance3D Designer
CVE-2026-34664

6.3MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
12 May 2026

What is CVE-2026-34664?

Adobe Substance3D Designer versions 15.1.0 and prior are vulnerable to a Path Traversal issue that allows attackers to read arbitrary files from the file system. This vulnerability arises when users open maliciously crafted files, which can relocate the scope of file access beyond what is intended. Successful exploitation could expose sensitive information stored on the user's system. Users should refrain from opening untrusted files until a patch has been applied.

Affected Version(s)

Substance3D - Designer 0 <= 15.1.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.