PT-2026-7423 · Adobe · Substance3D - Stager

Jann Horn

·

Published

2026-02-10

·

Updated

2026-02-10

·

CVE-2026-21342

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Substance3D - Stager versions 3.1.6 and earlier
Description The software contains a flaw that allows for writing data outside the intended memory boundaries. Successful exploitation of this issue could lead to arbitrary code execution with the privileges of the current user. User interaction is required for exploitation, specifically, a user must open a specially crafted malicious file.
Recommendations Update Substance3D - Stager to a version later than 3.1.6.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01893
CVE-2026-21342

Affected Products

Substance3D - Stager