CVE-2026-21303 is an Out-of-bounds Read vulnerability affecting Adobe Substance3D Modeler versions 1.22.4 and earlier. This flaw could lead to memory exposure, allowing an attacker to disclose sensitive information. The vulnerability has a CVSS score of 5.5 (Medium), requiring user interaction to open a malicious file for successful exploitation. There is no evidence of active exploitation, and no public exploit code is available, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.22.5CPE matchmatch criteria | cpe:2.3:a:adobe:substance_3d_modeler:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.