
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34683 is an out-of-bounds write vulnerability (CWE-787) in Adobe Substance 3D Designer that can result in arbitrary code execution and arbitrary file system read in the context of the current user. It affects Adobe Substance 3D Designer versions 15.1.0 and earlier. Adobe disclosed and patched this vulnerability on May 12, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory).
The vulnerability is rooted in an out-of-bounds write flaw (CWE-787) within Adobe Substance 3D Designer's file parsing logic. An attacker can craft a malicious file that, when opened by a victim, triggers the out-of-bounds write condition, potentially leading to arbitrary code execution or arbitrary file system reads. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted malicious file — but no elevated privileges are required (Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the Adobe Substance 3D Designer application and read arbitrary files from the file system, resulting in high confidentiality, integrity, and availability impact. The scope is limited to the current user's context, but sensitive project files, credentials, or other user data accessible to the application could be exposed. No lateral movement beyond the compromised user session is directly implied, though code execution could enable further post-exploitation activity (Adobe Advisory).
cmd.exe, powershell.exe, bash, curl, or other shells/utilities).Adobe has released a patch addressing this vulnerability; users should update Adobe Substance 3D Designer to a version newer than 15.1.0 as the primary remediation (Adobe Advisory). As a workaround, users should avoid opening untrusted or unexpected Substance 3D Designer files from unknown sources. Additionally, restricting file access permissions for the application and monitoring for suspicious file access patterns from the Substance 3D Designer process can reduce risk until patching is complete (CIS Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). No notable independent researcher commentary or significant social media discussion has been observed for this specific CVE beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."