CVE-2026-21341

7.8

Adobe · Substance3D Stager

Adobe Substance3D Stager versions 3.1.6 and earlier are susceptible to an out-of-bounds write vulnerability that could allow for arbitrary code execution via a specially crafted malicious file.

Executive summary

Adobe Substance3D Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that permits arbitrary code execution upon opening a malicious file.

Vulnerability

This vulnerability is an out-of-bounds write flaw (CWE-787) triggered when a user opens a malicious file within the application. The attack requires user interaction and can result in arbitrary code execution in the context of the current user.

Business impact

Successful exploitation allows an attacker to execute arbitrary code on the victim's workstation, potentially leading to full system compromise or unauthorized access to sensitive data. Given the CVSS score of 7.8, this is considered a High severity vulnerability that poses a significant risk to organizational endpoints where this software is utilized.

Remediation

Immediate Action: Update Adobe Substance3D Stager to version 3.1.7 or later to resolve the underlying vulnerability.

Proactive Monitoring: Review endpoint security logs for unexpected application crashes or unauthorized process execution associated with Adobe Substance3D Stager.

Compensating Controls: Implement file integrity monitoring and ensure users are educated regarding the risks of opening untrusted files from unknown sources.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this vulnerability necessitates immediate action, particularly in creative and design environments where third party files are frequently handled. Administrators should prioritize the deployment of the 3.1.7 update across all managed workstations to eliminate the risk of arbitrary code execution.

More Adobe CVEs

Sources