
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34664 is a Path Traversal vulnerability (CWE-22) in Adobe Substance 3D Designer that allows an attacker to read arbitrary files and directories outside the intended access scope. It affects Substance 3D Designer versions 15.1.0 and earlier. Adobe disclosed and patched this vulnerability on May 12, 2026. It carries a CVSS v3.1 base score of 6.3 (Medium) (Adobe Advisory).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and also associated with CWE-918 (Server-Side Request Forgery). The root cause is insufficient validation of file paths when processing project or asset files within Substance 3D Designer, allowing path traversal sequences (e.g., ../) to escape the intended directory boundary and access arbitrary file system locations. Exploitation requires a local attack vector and user interaction — specifically, a victim must open a specially crafted malicious file. The scope is marked as changed, indicating that the impact extends beyond the vulnerable component itself (Adobe Advisory).
Successful exploitation results in unauthorized read access to sensitive files and directories on the victim's file system that are outside the application's intended access scope. The primary impact is a high confidentiality loss, with no integrity or availability impact. An attacker could potentially access credentials, configuration files, or other sensitive data stored on the system, depending on the permissions of the user running Substance 3D Designer (Adobe Advisory).
.sbs or related format) that embeds path traversal sequences (e.g., ../../../../etc/passwd or ../../../../Windows/System32/config/SAM) in file reference fields or asset paths within the file structure..sbs, .sbsar) received from external sources; files containing path strings with ../ or URL-encoded equivalents (%2e%2e%2f) in asset reference fields.Adobe Substance 3D Designer.exe) accessing sensitive system directories (e.g., C:\Windows\System32\, /etc/, /home/) as observed via process monitoring tools such as Procmon or auditd.Adobe has released a patch addressing this vulnerability; users should update Substance 3D Designer to a version newer than 15.1.0 as soon as possible (Adobe Advisory). As interim mitigations, users should avoid opening Substance 3D Designer project files from untrusted or unknown sources. Organizations should educate users about the risks of opening files received via email or file-sharing services, and consider implementing application-level controls or file inspection policies to detect path traversal patterns in project files.
The CIS (Center for Internet Security) noted this vulnerability as part of a broader advisory covering multiple Adobe product vulnerabilities in May 2026, flagging the potential for arbitrary code execution across the Adobe product suite (CIS Advisory). No significant independent researcher commentary or social media discussion has been identified for this specific CVE, consistent with its medium severity rating and lack of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."