Description
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow in Adobe Substance 3D Sampler that can lead to arbitrary code execution in the context of the current user. This flaw, identified as CWE-122, occurs when the application processes an oversized or malformed file, allowing an attacker to overwrite memory and hijack control flow. An attacker who successfully overflows the buffer could execute arbitrary code, potentially gaining full control over the victim’s system.

Affected Systems

Adobe Substance 3D Sampler is the affected product. No specific version data is provided in the CVE entry, so all releases of this software are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity impact. Because exploitation requires the victim to open a malicious file, the attack vector is user‑interaction, which limits remote exploitation. EPSS data is not available, but the CVE is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not yet been observed. Nonetheless, the high severity and potential for arbitrary code execution warrant prompt remediation.

Generated by OpenCVE AI on August 25, 2026 at 20:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the patch for Adobe Substance 3D Sampler released in the security advisory at https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-121.html
  • Restart the application after the patch to apply the changes.
  • Avoid opening unknown or untrusted files with Substance 3D Sampler until the update is applied.

Generated by OpenCVE AI on August 25, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:46:00.961Z

Reserved: 2026-05-21T15:28:38.145Z

Link: CVE-2026-48425

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T18:17:54.183

Modified: 2026-08-25T18:17:54.183

Link: CVE-2026-48425

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:15:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow