CVE-2026-21345: Substance3D - Stager | Out-of-bounds Read (CWE-125)
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21345?
The CVE-2026-21345 vulnerability has a medium severity rating as it may allow attackers to read past allocated memory, potentially exposing sensitive information.
How do I fix CVE-2026-21345?
To fix CVE-2026-21345, upgrade Substance3D Stager to version 3.1.7 or later to mitigate the out-of-bounds read vulnerability.
What versions of Substance3D Stager are affected by CVE-2026-21345?
Substance3D Stager versions up to and including 3.1.6 are affected by CVE-2026-21345.
Can CVE-2026-21345 be exploited remotely?
CVE-2026-21345 could potentially be exploited by an attacker through a specially crafted file that triggers the out-of-bounds read.
What types of systems are vulnerable to CVE-2026-21345?
Vulnerable systems include those running affected versions of Substance3D Stager on platforms like Windows and macOS.