CVE-2026-21345

7.8

Adobe · Substance3D Stager

Adobe Substance3D Stager 3.1.6 and earlier is vulnerable to an out-of-bounds read flaw that could lead to arbitrary code execution when a user opens a specially crafted file.

Executive summary

Adobe Substance3D Stager contains an out-of-bounds read vulnerability that allows attackers to achieve remote code execution through user interaction.

Vulnerability

This is an out-of-bounds read vulnerability (CWE-125) triggered when parsing malicious files. Exploitation requires a victim to open the file, after which the attacker can execute code in the context of the current user.

Business impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the logged-in user, potentially leading to full system compromise. Given the CVSS score of 7.8, this represents a high-severity risk that could facilitate unauthorized data access or lateral movement within an organization.

Remediation

Immediate Action: Update Adobe Substance3D Stager to version 3.1.7 or later to implement the vendor-provided fix.

Proactive Monitoring: Monitor endpoint activity for unusual process spawns originating from the Substance3D Stager application.

Compensating Controls: Implement file integrity monitoring and restrict the execution of untrusted files from external sources to reduce the likelihood of a user opening a malicious document.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The vulnerability poses a severe threat due to the potential for arbitrary code execution. Organizations should prioritize updating all instances of Adobe Substance3D Stager to version 3.1.7 immediately to eliminate the underlying memory safety flaw.

More Adobe CVEs

Sources