CVE-2026-34664
Adobe Substance 3D Designer vulnerability analysis and mitigation

Overview

CVE-2026-34664 is a Path Traversal vulnerability (CWE-22) in Adobe Substance 3D Designer that allows an attacker to read arbitrary files and directories outside the intended access scope. It affects Substance 3D Designer versions 15.1.0 and earlier. Adobe disclosed and patched this vulnerability on May 12, 2026. It carries a CVSS v3.1 base score of 6.3 (Medium) (Adobe Advisory).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and also associated with CWE-918 (Server-Side Request Forgery). The root cause is insufficient validation of file paths when processing project or asset files within Substance 3D Designer, allowing path traversal sequences (e.g., ../) to escape the intended directory boundary and access arbitrary file system locations. Exploitation requires a local attack vector and user interaction — specifically, a victim must open a specially crafted malicious file. The scope is marked as changed, indicating that the impact extends beyond the vulnerable component itself (Adobe Advisory).

Impact

Successful exploitation results in unauthorized read access to sensitive files and directories on the victim's file system that are outside the application's intended access scope. The primary impact is a high confidentiality loss, with no integrity or availability impact. An attacker could potentially access credentials, configuration files, or other sensitive data stored on the system, depending on the permissions of the user running Substance 3D Designer (Adobe Advisory).

Exploitation steps

  1. Craft a malicious file: Create a Substance 3D Designer project file (e.g., .sbs or related format) that embeds path traversal sequences (e.g., ../../../../etc/passwd or ../../../../Windows/System32/config/SAM) in file reference fields or asset paths within the file structure.
  2. Deliver the malicious file: Distribute the crafted file to a target via phishing email, file-sharing platform, or other social engineering means, disguising it as a legitimate Substance 3D Designer project.
  3. Victim opens the file: The victim opens the malicious file in Substance 3D Designer version 15.1.0 or earlier, triggering the application to process the embedded path references.
  4. Path traversal triggers file read: The application fails to sanitize the traversal sequences and reads files from arbitrary locations on the file system outside the intended directory.
  5. Exfiltrate data: If the application renders or exposes the content of the traversed files (e.g., as textures, embedded resources, or error output), the attacker can recover sensitive file contents from the victim's system (Adobe Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited Substance 3D Designer project files (.sbs, .sbsar) received from external sources; files containing path strings with ../ or URL-encoded equivalents (%2e%2e%2f) in asset reference fields.
  • Logs: Application logs showing file access attempts to paths outside the Substance 3D Designer working directory or installation folder; errors referencing unexpected file paths during project load.
  • Process: Substance 3D Designer process (Adobe Substance 3D Designer.exe) accessing sensitive system directories (e.g., C:\Windows\System32\, /etc/, /home/) as observed via process monitoring tools such as Procmon or auditd.

Mitigation and workarounds

Adobe has released a patch addressing this vulnerability; users should update Substance 3D Designer to a version newer than 15.1.0 as soon as possible (Adobe Advisory). As interim mitigations, users should avoid opening Substance 3D Designer project files from untrusted or unknown sources. Organizations should educate users about the risks of opening files received via email or file-sharing services, and consider implementing application-level controls or file inspection policies to detect path traversal patterns in project files.

Community reactions

The CIS (Center for Internet Security) noted this vulnerability as part of a broader advisory covering multiple Adobe product vulnerabilities in May 2026, flagging the potential for arbitrary code execution across the Adobe product suite (CIS Advisory). No significant independent researcher commentary or social media discussion has been identified for this specific CVE, consistent with its medium severity rating and lack of public exploit code.

Additional resources


SourceThis report was generated using AI

Related Adobe Substance 3D Designer vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34684HIGH7.8
  • Adobe Substance 3D Designer logoAdobe Substance 3D Designer
  • cpe:2.3:a:adobe:substance_3d_designer
NoYesMay 12, 2026
CVE-2026-34683HIGH7.8
  • Adobe Substance 3D Designer logoAdobe Substance 3D Designer
  • cpe:2.3:a:adobe:substance_3d_designer
NoYesMay 12, 2026
CVE-2026-34682HIGH7.8
  • Adobe Substance 3D Designer logoAdobe Substance 3D Designer
  • cpe:2.3:a:adobe:substance_3d_designer
NoYesMay 12, 2026
CVE-2026-34681HIGH7.8
  • Adobe Substance 3D Designer logoAdobe Substance 3D Designer
  • cpe:2.3:a:adobe:substance_3d_designer
NoYesMay 12, 2026
CVE-2026-34664MEDIUM6.3
  • Adobe Substance 3D Designer logoAdobe Substance 3D Designer
  • cpe:2.3:a:adobe:substance_3d_designer
NoYesMay 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management