Description
Substance3D - Designer is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a NULL pointer dereference that causes Substance 3D Designer to crash, resulting in a denial‑of‑service condition. An attacker can invoke the crash by providing a specially crafted file that the application processes.

Affected Systems

Adobe Substance 3D Designer is affected. No specific version range is listed in the advisory, so all installations of the product are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity exploit. The EPSS score is not available and the issue is not listed in CISA KEV, suggesting the likelihood of widespread exploitation is low. The attack vector requires the victim to open a malicious file, so exploitation depends on user interaction. Once triggered, the application will stop responding, leading to a local denial of service.

Generated by OpenCVE AI on August 25, 2026 at 20:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Adobe’s latest security advisory and install any available update for Substance 3D Designer.
  • If no patch exists, restrict user access to potentially malicious files or run the application in a sandboxed environment.
  • Educate users that opening unknown files can crash the application and advise them to verify file integrity before opening.

Generated by OpenCVE AI on August 25, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Designer is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Designer | NULL Pointer Dereference (CWE-476)
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T19:04:46.259Z

Reserved: 2026-05-21T15:28:38.145Z

Link: CVE-2026-48429

cve-icon Vulnrichment

Updated: 2026-08-25T19:04:42.039Z

cve-icon NVD

Status : Received

Published: 2026-08-25T18:17:54.783

Modified: 2026-08-25T19:16:49.247

Link: CVE-2026-48429

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:15:04Z

Weaknesses