CVE-2026-21300
Unknown Unknown - Not Provided
NULL Pointer Dereference in Substance3D Modeler Causes DoS

Publication date: 2026-01-13

Last updated on: 2026-01-13

Assigner: Adobe Systems Incorporated

Description
Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-13
Last Modified
2026-01-13
Generated
2026-06-16
AI Q&A
2026-01-14
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
adobe substance3d_modeler to 1.22.4 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a NULL Pointer Dereference in Substance3D - Modeler versions 1.22.4 and earlier. It can cause the application to crash or become unavailable (denial-of-service) when a user opens a specially crafted malicious file.

Impact Analysis

The impact of this vulnerability is that an attacker could cause the Substance3D - Modeler application to crash or stop functioning by tricking a user into opening a malicious file, resulting in denial-of-service.

Mitigation Strategies

To mitigate this vulnerability, avoid opening malicious files in Substance3D - Modeler versions 1.22.4 and earlier. Consider updating to a later version if available, or restrict user interaction with untrusted files to prevent exploitation.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21300. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart