Security updates available for Substance 3D Designer | APSB26-52
摘要
Adobe has released an update for Adobe Substance 3D Designer that addresses important vulnerabilities. Successful exploitation could lead to arbitrary file system read and arbitrary code execution in the context of the current user.
正文
Adobe has released an update for Adobe Substance 3D Designer that addresses important vulnerabilities. Successful exploitation could lead to arbitrary file system read and arbitrary code execution in the context of the current user. Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates. Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version via the Creative Cloud desktop app's update mechanism. For more information, please reference this help page . For managed environments, IT administrators can use the Admin Console to deploy Creative Cloud applications to end users. Refer to this help page for more information. Affected products: - Adobe Substance 3D Designer | 15.1.0 and earlier versions | All Solutions: - Adobe Substance 3D Designer | 16.0.1 | All (Priority 3; Download Center) Vulnerabilities: - Server-Side Request Forgery (SSRF) ( CWE-918 ) | Arbitrary file system read | Important | CVSS 6.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N - Out-of-bounds Write ( CWE-787 ) | Arbitrary code execution | Important | CVSS 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - Out-of-bounds Write ( CWE-787 ) | Arbitrary code execution | Important | CVSS 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - Out-of-bounds Write ( CWE-787 ) | Arbitrary code execution | Important | CVSS 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - Out-of-bounds Write ( CWE-787 ) | Arbitrary code execution | Important | CVSS 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
标签
- contains:cve
- priority:3
- product:adobe-substance-3d-designer
- vendor:adobe
扩展字段
{
"affected_products": [
{
"platform": "All",
"product": "Adobe Substance 3D Designer",
"version": "15.1.0 and earlier versions"
}
],
"bulletin_id": "APSB26-52",
"detail_url": "https://helpx.adobe.com/security/products/substance3d_designer/apsb26-52.html",
"last_updated": "05/12/2026",
"originally_posted": "05/12/2026",
"priority": "3",
"solution_paragraphs": [
"Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version via the Creative Cloud desktop app's update mechanism. For more information, please reference this help page .",
"For managed environments, IT administrators can use the Admin Console to deploy Creative Cloud applications to end users. Refer to this help page for more information."
],
"solutions": [
{
"availability": "Download Center",
"availability_url": "https://www.adobe.com/products/substance3d-designer.html",
"platform": "All",
"priority": "3",
"product": "Adobe Substance 3D Designer",
"version": "16.0.1"
}
],
"summary_paragraphs": [
"Adobe has released an update for Adobe Substance 3D Designer that addresses important vulnerabilities. Successful exploitation could lead to arbitrary file system read and arbitrary code execution in the context of the current user.",
"Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates."
],
"vulnerabilities": [
{
"CVE Numbers": "CVE-2026-34664",
"CVSS base score": "6.3",
"CVSS vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N",
"Severity": "Important",
"Vulnerability Category": "Server-Side Request Forgery (SSRF) ( CWE-918 )",
"Vulnerability Impact": "Arbitrary file system read"
},
{
"CVE Numbers": "CVE-2026-34681",
"CVSS base score": "5.5",
"CVSS vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"Severity": "Important",
"Vulnerability Category": "Out-of-bounds Write ( CWE-787 )",
"Vulnerability Impact": "Arbitrary code execution"
},
{
"CVE Numbers": "CVE-2026-34682",
"CVSS base score": "5.5",
"CVSS vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"Severity": "Important",
"Vulnerability Category": "Out-of-bounds Write ( CWE-787 )",
"Vulnerability Impact": "Arbitrary code execution"
},
{
"CVE Numbers": "CVE-2026-34683",
"CVSS base score": "5.5",
"CVSS vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"Severity": "Important",
"Vulnerability Category": "Out-of-bounds Write ( CWE-787 )",
"Vulnerability Impact": "Arbitrary code execution"
},
{
"CVE Numbers": "CVE-2026-34684",
"CVSS base score": "5.5",
"CVSS vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"Severity": "Important",
"Vulnerability Category": "Out-of-bounds Write ( CWE-787 )",
"Vulnerability Impact": "Arbitrary code execution"
}
]
}