Description
Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-05-12
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Substance3D Designer versions 15.1.0 and earlier are vulnerable to a path traversal flaw that allows an attacker to read arbitrary files on the file system. The weakness enables access to sensitive files and directories outside the intended access scope, which could compromise confidentiality and potentially expose critical data. The issue is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory).

Affected Systems

The affected vendor is Adobe, specifically the Substance3D Designer product. All releases version 15.1.0 and earlier are impacted; newer releases are assumed fixed.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, while no EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires user interaction, meaning a victim must open a malicious file that contains a crafted path. The scope change indicates that the vulnerability can affect system-level resources. With the current exposure, an attacker who can trick a user into opening such a file could read files beyond the application’s intended directory containment, increasing risk to organizational data.

Generated by OpenCVE AI on May 12, 2026 at 20:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Substance3D Designer to a version where the path traversal fix is included.
  • Restrict user access to open untrusted or unknown files within the application by enforcing a whitelist of safe directories or disabling file opening from external sources.
  • Enable auditing or logging for file access events in the application to detect potential misuse or unauthorized file reads.

Generated by OpenCVE AI on May 12, 2026 at 20:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:adobe:substance_3d_designer:*:*:*:*:*:*:*:*

Wed, 13 May 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe substance 3d Designer
Vendors & Products Adobe
Adobe substance 3d Designer

Tue, 12 May 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 May 2026 19:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Substance3D - Designer | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}


Subscriptions

Adobe Substance 3d Designer
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-05-12T19:06:11.172Z

Reserved: 2026-03-30T17:30:36.494Z

Link: CVE-2026-34664

cve-icon Vulnrichment

Updated: 2026-05-12T19:06:04.386Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-12T19:16:31.157

Modified: 2026-05-13T19:40:05.580

Link: CVE-2026-34664

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T09:45:09Z

Weaknesses