CVE-2026-21341
7.8Adobe · Substance3D Stager
Adobe Substance3D Stager versions 3.1.6 and earlier are susceptible to an out-of-bounds write vulnerability that could allow for arbitrary code execution via a specially crafted malicious file.
Executive summary
Adobe Substance3D Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that permits arbitrary code execution upon opening a malicious file.
Vulnerability
This vulnerability is an out-of-bounds write flaw (CWE-787) triggered when a user opens a malicious file within the application. The attack requires user interaction and can result in arbitrary code execution in the context of the current user.
Business impact
Successful exploitation allows an attacker to execute arbitrary code on the victim's workstation, potentially leading to full system compromise or unauthorized access to sensitive data. Given the CVSS score of 7.8, this is considered a High severity vulnerability that poses a significant risk to organizational endpoints where this software is utilized.
Remediation
Immediate Action: Update Adobe Substance3D Stager to version 3.1.7 or later to resolve the underlying vulnerability.
Proactive Monitoring: Review endpoint security logs for unexpected application crashes or unauthorized process execution associated with Adobe Substance3D Stager.
Compensating Controls: Implement file integrity monitoring and ensure users are educated regarding the risks of opening untrusted files from unknown sources.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this vulnerability necessitates immediate action, particularly in creative and design environments where third party files are frequently handled. Administrators should prioritize the deployment of the 3.1.7 update across all managed workstations to eliminate the risk of arbitrary code execution.