CVE-2026-21365: Substance3D - Painter | Out-of-bounds Read (CWE-125)
Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21365?
CVE-2026-21365 has a significant severity rating due to its potential for memory exposure.
How do I fix CVE-2026-21365?
To fix CVE-2026-21365, update Substance3D Painter to version 11.1.3 or later.
What are the consequences of exploiting CVE-2026-21365?
Exploiting CVE-2026-21365 could allow an attacker to access sensitive information stored in memory.
Which versions of Substance3D Painter are affected by CVE-2026-21365?
Substance3D Painter versions 11.1.2 and earlier are affected by CVE-2026-21365.
Is there any workaround for CVE-2026-21365?
There are currently no known workarounds for CVE-2026-21365 apart from upgrading to a fixed version.