
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21363 is a NULL Pointer Dereference vulnerability in Adobe Substance 3D Painter that can cause application-level denial of service. It affects Substance 3D Painter versions 11.1.2 and earlier (all versions prior to 11.1.3). Adobe disclosed and patched this vulnerability on March 10, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory).
The vulnerability is classified as CWE-476 (NULL Pointer Dereference), occurring when the application attempts to dereference a null pointer during file parsing or processing. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted malicious file, triggering the null pointer dereference and causing the application to crash. No authentication is required on the attacker's part beyond the ability to deliver a malicious file to the victim (Adobe Advisory).
Successful exploitation results in an application-level denial of service, crashing Adobe Substance 3D Painter and disrupting any active work or services dependent on it. The vulnerability has no impact on confidentiality or integrity — only availability is affected, and the scope is limited to the application itself without privilege escalation or lateral movement potential (Adobe Advisory).
.spp) or asset files received from external or unknown sources.painter.exe) terminating abruptly shortly after opening a file, without user-initiated close action.Adobe has released Substance 3D Painter version 11.1.3, which addresses this vulnerability. Users should update to version 11.1.3 or later as the primary remediation. As a temporary workaround until patching is possible, users should avoid opening Substance 3D Painter files received from untrusted or unknown sources (Adobe Advisory).
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Adobe products patched in March 2026, including this issue, flagging potential for disruption to creative workflows (CIS Advisory). General community sentiment treats this as a low-urgency patch given the medium severity, lack of remote exploitability, and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."