Description
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Substance3D - Sampler is affected by an out‑of‑bounds write. The flaw allows a malicious document to overwrite memory and can lead to arbitrary code execution in the context of the user who opens the file. The vulnerability is a classic buffer overrun (CWE‑787) where uncontrolled data is written past a boundary, which can corrupt instruction pointers, flags or other critical structures used by the application.

Affected Systems

Adobe Substance 3D Sampler, all versions are potentially impacted because the CVE description does not specify any fixed releases or version ranges.

Risk and Exploitability

The CVSS score of 7.8 indicates a high impact if the flaw is triggered. Exploitation requires the victim to open a crafted file, so it is a user‑interaction risk. The EPSS score is unavailable, but the lack of listing in the CISA KEV catalog suggests no confirmed exploitation at this time. Nevertheless, the combination of high severity and user‑triggered activation warrants immediate attention.

Generated by OpenCVE AI on August 25, 2026 at 20:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest version of Adobe Substance 3D Sampler that contains the patch for the out-of-bounds write.
  • If no update is available, avoid opening documents from untrusted sources and consider disabling the default file association for the application or running it in a sandboxed environment.
  • Review and enforce strict file‑type restrictions by configuring operating‑system security settings to prevent automatic execution of unverified files.
  • Ensure the operating system, antivirus, and other endpoint protection tools are current and perform regular scans for malicious content.

Generated by OpenCVE AI on August 25, 2026 at 20:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Sampler | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:45:57.334Z

Reserved: 2026-05-21T15:28:38.145Z

Link: CVE-2026-48420

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T18:17:53.450

Modified: 2026-08-25T18:17:53.450

Link: CVE-2026-48420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:15:04Z

Weaknesses