Description
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

Substance3D - Sampler is affected by an out‑of‑bounds write. The flaw allows a malicious document to overwrite memory and can lead to arbitrary code execution in the context of the user who opens the file. The vulnerability is a classic buffer overrun (CWE‑787) where uncontrolled data is written past a boundary, which can corrupt instruction pointers, flags or other critical structures used by the application.

Affected Systems

Adobe Substance 3D Sampler, all versions are potentially impacted because the CVE description does not specify any fixed releases or version ranges.

Risk and Exploitability

The CVSS score of 7.8 indicates a high impact if the flaw is triggered. Exploitation requires the victim to open a crafted file, so it is a user‑interaction risk. The EPSS score is unavailable, but the lack of listing in the CISA KEV catalog suggests no confirmed exploitation at this time. Nevertheless, the combination of high severity and user‑triggered activation warrants immediate attention.

Generated by OpenCVE AI on August 25, 2026 at 20:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest version of Adobe Substance 3D Sampler that contains the patch for the out-of-bounds write.
  • If no update is available, avoid opening documents from untrusted sources and consider disabling the default file association for the application or running it in a sandboxed environment.
  • Review and enforce strict file‑type restrictions by configuring operating‑system security settings to prevent automatic execution of unverified files.
  • Ensure the operating system, antivirus, and other endpoint protection tools are current and perform regular scans for malicious content.

Generated by OpenCVE AI on August 25, 2026 at 20:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe substance 3d Sampler
CPEs cpe:2.3:a:adobe:substance_3d_sampler:*:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe substance 3d Sampler

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Sampler | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Substance 3d Sampler
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:32:41.914Z

Reserved: 2026-05-21T15:28:38.145Z

Link: CVE-2026-48420

cve-icon Vulnrichment

Updated: 2026-08-27T16:14:32.975Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T18:17:53.450

Modified: 2026-08-28T00:41:46.453

Link: CVE-2026-48420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:15:04Z

Weaknesses