Description
Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Substance3D Painter is vulnerable to an out‑of‑bounds read that allows an attacker to read sensitive memory contents. The flaw can expose confidential data but does not allow arbitrary code execution or system compromise. The weakness is a classic boundary validation error, as identified by CWE‑125.

Affected Systems

Adobe Substance 3D Painter products are affected. The vulnerability does not list specific version ranges, so all installations that have not applied the latest security update are potentially at risk.

Risk and Exploitability

The CVSS score of 5.5 indicates a medium‑severity disclosure risk. EPSS is not available, and the vulnerability is not listed in CISA KEV, so no evidence suggests active exploitation. The attack requires the victim to open a malicious file, meaning the vector is local and user‑initiated. In the absence of further exploitation reports, the risk remains moderate but tangible for environments that handle sensitive data.

Generated by OpenCVE AI on August 25, 2026 at 20:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest Adobe Substance 3D Painter release that addresses the out‑of‑bounds read flaw.
  • Avoid opening untrusted or unknown files with Substance 3D Painter until a patch is installed.
  • When a vendor release is unavailable, restrict file access permissions to limit the impact of potential memory disclosure.

Generated by OpenCVE AI on August 25, 2026 at 20:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe substance 3d Painter
Vendors & Products Adobe
Adobe substance 3d Painter

Tue, 25 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Painter | Out-of-bounds Read (CWE-125)
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Substance 3d Painter
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:58:11.743Z

Reserved: 2026-08-18T01:29:54.623Z

Link: CVE-2026-75752

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T18:18:03.670

Modified: 2026-08-25T18:18:03.670

Link: CVE-2026-75752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:15:04Z

Weaknesses