CVE-2026-21344
7.8Adobe · Substance3D Stager
Adobe Substance3D Stager is affected by an out-of-bounds read vulnerability that may allow an attacker to execute arbitrary code via a specially crafted file.
Executive summary
Adobe Substance3D Stager versions 3.1.6 and earlier are vulnerable to an out-of-bounds read flaw that could lead to remote code execution upon opening a malicious file.
Vulnerability
This vulnerability is an out-of-bounds read (CWE-125) triggered when the application parses a malformed file. The attacker requires user interaction, as a victim must open the malicious file, but once opened, the code executes in the context of the current user.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve arbitrary code execution on the host machine. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, loss of data integrity, and unauthorized access to sensitive information stored on the user's workstation.
Remediation
Immediate Action: Update Adobe Substance3D Stager to version 3.1.7 or later as specified in the official vendor security advisory.
Proactive Monitoring: Monitor endpoint activity for suspicious file parsing behaviors or unexpected subprocesses spawned by the Substance3D Stager application.
Compensating Controls: Ensure that users are restricted from opening files from untrusted sources and utilize endpoint detection and response tools to identify anomalous memory access patterns.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a significant risk to workstations running Adobe Substance3D Stager due to the potential for arbitrary code execution. Organizations should prioritize updating all instances of the software to version 3.1.7 or later to eliminate the underlying memory corruption flaw and protect system environments from potential exploitation.