Description
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Patch Now
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in Adobe Substance 3D Sampler that can be exploited to execute arbitrary code with the privileges of the current user. It arises from incorrect bounds checking when processing user supplied data, a weakness identified as CWE‑787. The attack can lead to full compromise of the affected system if the victim executes code without further isolation.

Affected Systems

Adobe offers Substance 3D Sampler as the affected product. No specific version numbers are provided in the advisory, indicating that all versions prior to the fix are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 signifies a high severity rating. The EPSS score is unavailable, but the vulnerability requires the victim to open a malicious file, so it is a user‑interaction exploit. Because it is not listed in the CISA KEV catalog, no current widespread exploitation is reported, yet the high severity and reliance on local file handling present a significant risk for environments that process untrusted 3D asset files.

Generated by OpenCVE AI on August 25, 2026 at 20:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Adobe's security update (APSB26-121) to Substance 3D Sampler.
  • Avoid opening files from untrusted or unknown sources in the Substance application.
  • Configure file‑type restrictions or local policies to prevent automatic opening of untrusted 3D assets.

Generated by OpenCVE AI on August 25, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe substance 3d Sampler
CPEs cpe:2.3:a:adobe:substance_3d_sampler:*:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe substance 3d Sampler

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Sampler | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Substance 3d Sampler
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:32:37.116Z

Reserved: 2026-05-21T15:28:38.145Z

Link: CVE-2026-48421

cve-icon Vulnrichment

Updated: 2026-08-27T16:14:29.981Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T18:17:53.583

Modified: 2026-08-28T00:37:57.090

Link: CVE-2026-48421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:15:04Z

Weaknesses