Description
Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds write condition in Adobe Substance 3D Painter that can lead to arbitrary code execution in the current user’s context. This flaw allows an attacker to run malicious instructions after the user opens a crafted file. The weakness is identified as CWE‑787, a classic buffer overflow that undermines data integrity and confidentiality for the affected user.

Affected Systems

Adobe’s Substance 3D Painter is the only product listed. No specific version numbers are provided in the current entry; security teams should verify installations against the vendor’s advisory and determine whether their current builds contain the flaw.

Risk and Exploitability

The CVSS score of 7.8 reflects a high risk of compromise, and the vulnerability is listed as not in the CISA Key‑Exploited Vulnerabilities catalog. EPSS data is unavailable, so precise exploitation probability cannot be quantified. However, the flaw requires a victim to open a malicious file, indicating that the attack vector is user‑initiated and generally local or shared. Once executed, the attacker gains the privileges of the victim, potentially compromising the entire system and any data accessed by that user.

Generated by OpenCVE AI on August 25, 2026 at 20:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official security update released by Adobe for Substance 3D Painter.
  • Reject or quarantine any unfamiliar files before opening them to prevent accidental execution of malicious content.
  • Review user permissions and limit access to critical file types for users lacking administrative rights; enforce the principle of least privilege.

Generated by OpenCVE AI on August 25, 2026 at 20:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe substance 3d Painter
Vendors & Products Adobe
Adobe substance 3d Painter

Tue, 25 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Painter | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Substance 3d Painter
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:58:12.441Z

Reserved: 2026-08-18T03:42:49.427Z

Link: CVE-2026-75770

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T18:18:04.403

Modified: 2026-08-25T18:18:04.403

Link: CVE-2026-75770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T19:45:04Z

Weaknesses