Out-of-Bounds Write Vulnerability in Substance3D Designer Software by Adobe
CVE-2026-34681

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
12 May 2026

What is CVE-2026-34681?

Substance3D Designer versions 15.1.0 and earlier present an out-of-bounds write vulnerability that can lead to arbitrary code execution if a user opens a specially crafted malicious file. This exploit necessitates user interaction, making it critical for users to be cautious when handling unknown files. Detailed guidance can be found in Adobe's security advisory.

Affected Version(s)

Substance3D - Designer 0 <= 15.1.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.