
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21334 is an out-of-bounds write vulnerability in Adobe Substance 3D Designer that can result in arbitrary code execution in the context of the current user. It affects Substance 3D Designer versions 15.1.0 and earlier (all versions prior to 15.1.2). Adobe disclosed and patched this vulnerability on February 10, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), where the application writes data beyond the bounds of an allocated memory buffer during file parsing. Exploitation requires a local attack vector — an attacker must deliver a specially crafted malicious file that the victim opens within Substance 3D Designer. No elevated privileges are required by the attacker, but user interaction (opening the file) is a necessary precondition. No public proof-of-concept or detailed technical write-up has been identified at this time (Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Adobe Substance 3D Designer, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could potentially read sensitive files, modify data, install malware, or cause application crashes. The scope is limited to the local user context, but could serve as a foothold for further lateral movement if the compromised account has broader network access (Adobe Advisory).
.sbs or similar Substance Designer format) that triggers an out-of-bounds write when parsed by the application.cmd.exe, powershell.exe, bash, curl, wget).Adobe has released version 15.1.2 of Substance 3D Designer, which addresses this vulnerability. Users should update to version 15.1.2 or later immediately via the Creative Cloud desktop application or Adobe's official download channels. As an interim workaround, users should avoid opening Substance 3D Designer files received from untrusted or unknown sources. Organizations should consider applying application allowlisting and user education around file-based social engineering attacks (Adobe Advisory).
The CIS (Center for Internet Security) published an advisory noting that multiple Adobe vulnerabilities patched in February 2026, including this one, could allow for arbitrary code execution, recommending prompt patching. Coverage was also noted from security aggregators such as Tenable, BeyondMachines, and Fortress SRM in their February 2026 threat update roundups. No significant independent researcher commentary or social media discussion has been identified for this specific CVE, consistent with its low EPSS score and absence of public exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."