Description
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in Adobe Substance 3D Sampler that can be exploited to execute arbitrary code with the privileges of the current user. It arises from incorrect bounds checking when processing user supplied data, a weakness identified as CWE‑787. The attack can lead to full compromise of the affected system if the victim executes code without further isolation.

Affected Systems

Adobe offers Substance 3D Sampler as the affected product. No specific version numbers are provided in the advisory, indicating that all versions prior to the fix are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 signifies a high severity rating. The EPSS score is unavailable, but the vulnerability requires the victim to open a malicious file, so it is a user‑interaction exploit. Because it is not listed in the CISA KEV catalog, no current widespread exploitation is reported, yet the high severity and reliance on local file handling present a significant risk for environments that process untrusted 3D asset files.

Generated by OpenCVE AI on August 25, 2026 at 20:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Adobe's security update (APSB26-121) to Substance 3D Sampler.
  • Avoid opening files from untrusted or unknown sources in the Substance application.
  • Configure file‑type restrictions or local policies to prevent automatic opening of untrusted 3D assets.

Generated by OpenCVE AI on August 25, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Sampler | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:46:00.191Z

Reserved: 2026-05-21T15:28:38.145Z

Link: CVE-2026-48421

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T18:17:53.583

Modified: 2026-08-25T18:17:53.583

Link: CVE-2026-48421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:15:04Z

Weaknesses