Description
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Substance 3D Sampler contains an out‑of‑bounds write flaw that can be triggered by loading a specially crafted file. This bug allows an attacker to corrupt memory adjacent to the intended buffer, enabling the execution of attacker‑supplied code in the context of the current user. The vulnerability is a classic example of a buffer overwrite (CWE‑787).

Affected Systems

The Adobe Substance 3D Sampler application is the affected product. No specific version numbers are listed in the advisory, so all installations of the product prior to the published patch are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity impact. Because exploitation requires a victim to open a malicious file, the attack vector is user interaction (local). The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known mass exploitation at this time. Nonetheless, the ability to achieve arbitrary execution can have catastrophic consequences, so the risk warrants immediate remediation.

Generated by OpenCVE AI on August 25, 2026 at 20:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official security update for Adobe Substance 3D Sampler as distributed by Adobe (see the advisory link).
  • Configure the system or the application to prompt for confirmation before opening files, or use sandboxing to limit the process’s privileges when loading external content.
  • Educate users to only open Substance 3D Sampler files from trusted and verified sources to avoid accidental execution of malicious content.

Generated by OpenCVE AI on August 25, 2026 at 20:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Sampler | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:45:58.765Z

Reserved: 2026-05-21T15:28:38.145Z

Link: CVE-2026-48418

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T18:17:53.160

Modified: 2026-08-25T18:17:53.160

Link: CVE-2026-48418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:15:04Z

Weaknesses