Description
Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Patch
AI Analysis

Impact

An out‑of‑bounds write vulnerability in Adobe Substance 3D Designer allows an attacker to overwrite memory beyond a buffer’s limits. This flaw can be exploited to execute arbitrary code in the context of the user who opens a malicious file. The vulnerability is identified as CWE‑787 and the official description notes that exploitation requires user interaction by opening a specially crafted file.

Affected Systems

Adobe Substance 3D Designer from Adobe is the affected product. No specific version ranges are listed in the provided data, so any installer or packaged product that includes the vulnerable code is potentially impacted until an update is applied.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.8, which reflects high impact and moderate to high exploitability. EPSS data is unavailable, and the issue is not listed in the CISA KEV catalog. Exploitation requires that the victim be deceived into opening a malicious file, indicating a user‑interaction vector. Overall risk is substantial for users who open unknown files, especially if the latest patches have not been applied.

Generated by OpenCVE AI on August 25, 2026 at 20:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Adobe Substance 3D Designer update or patch that eliminates the out‑of‑bounds write flaw
  • Configure the application or operating system to require explicit user approval before automatically opening files, reducing the chance of accidental execution
  • Educate users to identify and avoid suspicious or unknown files, especially those received over email or from untrusted sources

Generated by OpenCVE AI on August 25, 2026 at 20:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe substance 3d Designer
CPEs cpe:2.3:a:adobe:substance_3d_designer:*:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe substance 3d Designer

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Designer | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Substance 3d Designer
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:32:45.240Z

Reserved: 2026-05-21T15:28:38.145Z

Link: CVE-2026-48426

cve-icon Vulnrichment

Updated: 2026-08-27T16:14:54.396Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T18:17:54.330

Modified: 2026-08-28T00:18:00.400

Link: CVE-2026-48426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:15:04Z

Weaknesses