CVE-2026-21344

7.8

Adobe · Substance3D Stager

Adobe Substance3D Stager is affected by an out-of-bounds read vulnerability that may allow an attacker to execute arbitrary code via a specially crafted file.

Executive summary

Adobe Substance3D Stager versions 3.1.6 and earlier are vulnerable to an out-of-bounds read flaw that could lead to remote code execution upon opening a malicious file.

Vulnerability

This vulnerability is an out-of-bounds read (CWE-125) triggered when the application parses a malformed file. The attacker requires user interaction, as a victim must open the malicious file, but once opened, the code executes in the context of the current user.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve arbitrary code execution on the host machine. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, loss of data integrity, and unauthorized access to sensitive information stored on the user's workstation.

Remediation

Immediate Action: Update Adobe Substance3D Stager to version 3.1.7 or later as specified in the official vendor security advisory.

Proactive Monitoring: Monitor endpoint activity for suspicious file parsing behaviors or unexpected subprocesses spawned by the Substance3D Stager application.

Compensating Controls: Ensure that users are restricted from opening files from untrusted sources and utilize endpoint detection and response tools to identify anomalous memory access patterns.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a significant risk to workstations running Adobe Substance3D Stager due to the potential for arbitrary code execution. Organizations should prioritize updating all instances of the software to version 3.1.7 or later to eliminate the underlying memory corruption flaw and protect system environments from potential exploitation.

More Adobe CVEs

Sources