CVE-2026-21343

7.8

Adobe · Substance3D Stager

Adobe Substance3D Stager versions 3.1.6 and earlier contain an out-of-bounds read flaw that can be leveraged by an attacker to execute arbitrary code via a maliciously crafted file.

Executive summary

Adobe Substance3D Stager is affected by a critical out-of-bounds read vulnerability that allows for arbitrary code execution when a user opens a specially crafted file.

Vulnerability

This vulnerability is an out-of-bounds read (CWE-125) occurring during the parsing of files, which allows an attacker to read past allocated memory structures. The exploit requires user interaction, specifically for a victim to open a malicious file, and operates in the context of the current user.

Business impact

The potential for arbitrary code execution poses a significant risk to organizational security, as it could allow an attacker to gain control over the victim's workstation. Given the CVSS score of 7.8, this vulnerability is classified as High, reflecting the serious impact on confidentiality, integrity, and availability should a successful compromise occur.

Remediation

Immediate Action: Update Adobe Substance3D Stager to version 3.1.7 or later as specified in the vendor security advisory.

Proactive Monitoring: Monitor endpoint activity for unusual application behavior or unauthorized processes spawned by the Substance3D Stager executable.

Compensating Controls: Implement strict file handling policies and utilize endpoint protection software to scan incoming files for malicious patterns before they are opened by users.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations should prioritize the deployment of the 3.1.7 update for all instances of Adobe Substance3D Stager to remediate this vulnerability. Given the risk of code execution, users should be reminded to exercise caution when opening files from untrusted or unexpected sources.

More Adobe CVEs

Sources