
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39020 is a denial-of-service vulnerability in Wings3D v.2.4.1, an open-source 3D modeler, that allows a local attacker to crash the application by opening a specially crafted Wavefront OBJ file. The vulnerability was published on September 9, 2026, and is classified as Moderate severity with a CVSS v3.1 base score of 5.5 (GitHub Advisory). The CVE status is currently listed as "Deferred" by the assigning authority (Feedly).
The root cause is classified as CWE-20 (Improper Input Validation), where Wings3D v.2.4.1 fails to adequately validate the contents of Wavefront OBJ files during import, allowing malformed data to trigger an application crash (GitHub Advisory). The attack vector is local, requires no privileges, but does require user interaction — specifically, a victim must open the malicious OBJ file within the application. The attack complexity is low, meaning no special conditions or bypass techniques are needed beyond convincing a user to open the crafted file (GitHub Advisory).
Successful exploitation results in a denial-of-service condition, crashing the Wings3D application and causing a high availability impact with no effect on confidentiality or integrity (GitHub Advisory). The impact is limited to the local application instance; there is no evidence of lateral movement potential, privilege escalation, or data exposure risk associated with this vulnerability. The scope is unchanged, meaning the impact is confined to the Wings3D process itself (Feedly).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and the EPSS score is 0.0, indicating a very low probability of exploitation in the near term. No threat actor attribution has been reported (Feedly).
.obj files in user directories or shared folders, particularly those with unusual file sizes or malformed content..dmp files or Linux core dumps).wings3d.exe or equivalent) shortly after opening an OBJ file, without user-initiated closure.No official patch has been confirmed for Wings3D v.2.4.1 at the time of publication; patched version details are listed as unknown in the GitHub Advisory Database (GitHub Advisory). As interim mitigations, users should avoid opening Wavefront OBJ files from untrusted or unknown sources, restrict OBJ file access permissions to trusted users only, and consider disabling OBJ file import functionality if it is not operationally required (Feedly). Users should monitor the Wings3D project repository for patch releases and upgrade as soon as a fixed version becomes available.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."