Description
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an out‑of‑bounds write in Adobe Substance 3D Sampler that can lead to arbitrary code execution. The flaw allows an attacker to corrupt data beyond an allocated buffer, potentially enabling the execution of malicious code in the victim’s user context. Because the vulnerability lies in memory handling during file processing, correct error handling would prevent the exploit.

Affected Systems

The affected product is Adobe Substance 3D Sampler. Version information is not disclosed in the current advisory, so any installed instance may be vulnerable until the vendor releases a fix.

Risk and Exploitability

The CVSS score of 7.8 indicates a high impact severity, while no EPSS data is available. The flaw is not part of the CISA KEV catalog. Exploit requires user interaction; the attacker must craft a malicious file and persuade a user to open it. The attack surface is limited to those who have downloaded or received such a file, but the resulting code execution would run with the victim’s privileges.

Generated by OpenCVE AI on August 25, 2026 at 20:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Substance 3D Sampler to the latest version provided by Adobe.
  • Avoid opening files from untrusted or unknown sources.
  • Use antivirus or file‑integrity checks before opening suspicious files.

Generated by OpenCVE AI on August 25, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe substance 3d Sampler
Vendors & Products Adobe
Adobe substance 3d Sampler
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Sampler | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Substance 3d Sampler
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T18:57:33.112Z

Reserved: 2026-08-06T09:00:49.999Z

Link: CVE-2026-71382

cve-icon Vulnrichment

Updated: 2026-08-25T18:57:28.706Z

cve-icon NVD

Status : Received

Published: 2026-08-25T18:18:00.477

Modified: 2026-08-25T19:16:52.843

Link: CVE-2026-71382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:15:04Z

Weaknesses