PatchSiren cyber security CVE debrief
CVE-2026-21348 Adobe CVE debrief
Substance3D - Modeler versions 1.22.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. This vulnerability, classified as an out-of-bounds read issue, can be triggered by processing a specially crafted file, potentially disclosing sensitive information stored in memory. Exploitation requires user interaction, as a victim must open a malicious file. The CVE record was published on 2026-02-10T20:16:55.420Z and has not been modified since then. Users of Substance3D - Modeler versions 1.22.5 and earlier, as well as administrators and security teams responsible for patching and vulnerability management, should review and apply vendor patches. Additionally, operators and platform administrators may need to assess the potential impact on their deployments and take compensating controls if necessary. Security teams should prioritize patching and monitor system logs for suspicious activity related to this vulnerability.
- Vendor
- Adobe
- Product
- Substance3D - Modeler
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-10
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-02-10
- Advisory updated
- 2026-08-28
Who should care
Users of Substance3D - Modeler versions 1.22.5 and earlier, as well as administrators and security teams responsible for patching and vulnerability management, should review and apply vendor patches. Additionally, operators and platform administrators may need to assess the potential impact on their deployments and take compensating controls if necessary. Security teams should prioritize patching and monitor system logs for suspicious activity related to this vulnerability. Vulnerability management teams should verify affected scope and assess potential operational impact. Asset inventory and change management processes may need to be updated to address this vulnerability. Security teams should also review and implement memory protection mechanisms to mitigate potential exposure. IT teams responsible for system updates and patch management should ensure that Substance3D - Modeler is updated to a version that is not vulnerable. Furthermore, incident response teams should be prepared to handle potential exploitation attempts and have plans in place for rapid response and remediation. Compliance and risk management teams may also need to assess the potential impact on their organization's risk profile and ensure that appropriate measures are taken to mitigate the risk associated with this vulnerability. Finally, developers and software engineers may need to review and update their code to prevent similar vulnerabilities in the future. The CVE record was published on 2026-02-10T20:16:55.420Z and has not been modified since then, indicating that the information provided is current and accurate as of that date. However, it is essential to note that the CVE record may not be updated if new information becomes available, and users should continue to monitor for updates from the vendor and other reliable sources. The CVE Program record and NIST NVD detail page provide further information on this vulnerability, including its CVSS score and severity rating. Users should consult these resources for additional details on the vulnerability and its potential impact. In addition to patching, users should consider implementing compensating controls, such as restricting access to
Technical summary
Substance3D - Modeler versions 1.22.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability is classified as an out-of-bounds read issue, which can be triggered by processing a specially crafted file.
Defensive priority
Medium-priority defensive review recommended due to potential for sensitive information disclosure.
Recommended defensive actions
- Review and apply vendor patches for Substance 3D Modeler
- Restrict access to sensitive files and directories
- Monitor system logs for suspicious activity
- Implement memory protection mechanisms
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page indicates an out-of-bounds read vulnerability in Substance3D - Modeler versions 1.22.5 and earlier. Limited information available on exploitation. Further review of system logs and memory protection mechanisms is recommended to verify exposure and potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-21348 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-21348
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-21348 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21348
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/substance3d-modeler/apsb26-22.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.