Description
Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Patch
AI Analysis

Impact

Substance3D Painter has an out-of-bounds write flaw that can lead to arbitrary code execution in the user’s security context. The vulnerability is a classic memory corruption bug, specifically relating to buffer overflow weaknesses (CWE-787). When triggered, it allows an attacker to overwrite adjacent memory and gain control of the program flow, potentially leading to full compromise of the affected user’s system.

Affected Systems

The impact is limited to Adobe Substance 3D Painter. No specific version information is listed in the CNA data, so all installations of Substance 3D Painter are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability, and the lack of an EPSS score means current exploitation likelihood is unknown. The flaw requires user interaction: a malicious file must be opened, so it is considered an in-lieu of remote attack a local or social engineering scenario. The vulnerability is not listed in the CISA KEV catalog, but patching remains the recommended approach.

Generated by OpenCVE AI on August 25, 2026 at 20:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Adobe Substance 3D Painter patch released by Adobe
  • Configure the application to restrict file types to trusted sources, limiting the ability to open malicious files
  • Run Substance 3D Painter in a sandboxed environment or with the least privilege required to mitigate potential exploitation

Generated by OpenCVE AI on August 25, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe substance 3d Painter
CPEs cpe:2.3:a:adobe:substance_3d_painter:*:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe substance 3d Painter

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Painter | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Substance 3d Painter
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:32:36.118Z

Reserved: 2026-08-18T01:29:54.623Z

Link: CVE-2026-75749

cve-icon Vulnrichment

Updated: 2026-08-27T16:14:13.169Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T18:18:03.360

Modified: 2026-08-31T18:02:10.123

Link: CVE-2026-75749

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:00:04Z

Weaknesses