Description
Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-22
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability is an out-of-bounds write in Substance3D Modeler that could allow an attacker to execute arbitrary code within the victim’s user context. This flaw occurs when processing a malicious model file, and it can lead to full compromise of the user’s system if exploited. The weakness aligns with CWE‑787, which concerns improper bounds checking leading to buffer overflows.

Affected Systems

The affected vendor is Adobe, specifically its Substance3D Modeler application. No specific version numbers are provided in the advisory, so all releases currently in use are potentially vulnerable until an official patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. Because exploitation requires the user to open a crafted file, the attack vector is local file and user interaction. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not a commonly exploited vulnerability today, but still poses a serious risk if a malicious file is introduced.

Generated by OpenCVE AI on September 22, 2026 at 21:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest security update for Adobe Substance3D Modeler as published in the Adobe security advisory.
  • Do not open unknown or untrusted files with Substance3D Modeler; verify file provenance before loading.
  • Enable application sandboxing or restrict the executable permissions for Substance3D Modeler files to limit the impact of a potential compromise.

Generated by OpenCVE AI on September 22, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Modeler | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T19:18:29.799Z

Reserved: 2026-08-25T14:55:21.139Z

Link: CVE-2026-79906

cve-icon Vulnrichment

Updated: 2026-09-22T19:18:21.007Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:52.097

Modified: 2026-09-22T20:17:09.120

Link: CVE-2026-79906

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:15:07Z

Weaknesses