Server-Side Request Forgery (SSRF) in Adobe Substance 3D Designer - CVE-2026-34664
Published: May 21, 2026
Adobe Substance 3D Designer
Detailed vulnerability description
The vulnerability allows a remote attacker to read arbitrary files.
The vulnerability exists due to server-side request forgery in Adobe Substance 3D Designer when processing attacker-controlled content. A remote attacker can supply crafted input to trigger arbitrary file system read.
User interaction is required to open or process crafted content.