CVE-2026-21348: Substance3D - Modeler | Out-of-bounds Read (CWE-125)
Substance3D - Modeler versions 1.22.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21348?
CVE-2026-21348 is considered to be a high severity vulnerability due to its potential for disclosing sensitive information.
How do I fix CVE-2026-21348?
To mitigate CVE-2026-21348, update Substance3D Modeler to version 1.22.6 or later.
What types of software are affected by CVE-2026-21348?
CVE-2026-21348 affects all versions of Substance3D Modeler up to and including version 1.22.5.
What kind of attacks can exploit CVE-2026-21348?
CVE-2026-21348 can be exploited through out-of-bounds read attacks that may lead to information disclosure.
Can CVE-2026-21348 be exploited remotely?
Yes, CVE-2026-21348 can potentially be exploited remotely by attackers with access to the vulnerable software.