CVE-2026-21363 PUBLISHED

Substance3D - Painter | NULL Pointer Dereference (CWE-476)

Assigner: adobe
Reserved: 12.12.2025 Published: 10.03.2026 Updated: 10.03.2026

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS Score: 5.5

Product Status

Vendor Adobe
Product Substance3D - Painter
Versions Default: affected
  • affected from 0 to 11.1.2 (incl.)

References

Problem Types

  • NULL Pointer Dereference (CWE-476) CWE