Description
Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution in the context of the current user.
Action: Assess Impact
AI Analysis

Impact

Substance3D Designer is vulnerable to an out‑of‑bounds write that could allow arbitrary code execution in the context of the user. The flaw arises when the application processes a malicious file, resulting in a buffer overflow that writes data outside the intended memory region. This category of vulnerability is identified as CWE-787.

Affected Systems

Adobe Substance 3D Designer is affected. No specific product versions are listed in the vulnerability data, so any installation of the product may need to be monitored until a vendor update is released.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.8, indicating a high severity level. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is user interaction, as a victim must open a malicious file for exploitation. Because the flaw enables arbitrary code execution, the impact spans confidentiality, integrity, and availability of the compromised system. The lack of publicly available exploit statistics means that the real‑world exploitation risk is uncertain but potentially significant for users who accept untrusted files.

Generated by OpenCVE AI on August 25, 2026 at 20:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Adobe’s official patch for Substance 3D Designer as soon as it becomes available.
  • Configure the software or operating system to require explicit user confirmation before opening any .s3d files or other proprietary file types.
  • Validate or sanitize file contents before opening, for example by using an antivirus scanner or sandboxed environment to isolate the file processing operation.

Generated by OpenCVE AI on August 25, 2026 at 20:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe substance 3d Designer
CPEs cpe:2.3:a:adobe:substance_3d_designer:*:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe substance 3d Designer

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Designer | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Substance 3d Designer
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:32:48.154Z

Reserved: 2026-08-07T11:08:35.214Z

Link: CVE-2026-71564

cve-icon Vulnrichment

Updated: 2026-08-27T16:14:39.167Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T18:18:01.790

Modified: 2026-08-28T00:18:11.163

Link: CVE-2026-71564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:45:04Z

Weaknesses