Description
Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-22
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

An out‑of‑bounds write allows attacker‑controlled data to corrupt memory and execute arbitrary code in the context of the user who opens a malicious file. The flaw could let a malicious actor run any code the authenticated user can, exposing the system to full compromise.

Affected Systems

Adobe Substance3D -- Modeler is affected. No specific release numbers are disclosed in the advisory.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.8, indicating a high chance of serious impact. The advisory notes that exploitation requires user interaction – the victim must open a crafted file. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, so the likelihood of widespread automated exploitation appears limited. Nonetheless, because of the potential for full code execution, the risk is significant for any environment that allows users to open arbitrary model files.

Generated by OpenCVE AI on September 22, 2026 at 21:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Substance3D -- Modeler to the latest version that addresses the out‑of‑bounds write flaw
  • If an update is not immediately available, restrict the use of the application to trusted personnel or disable it for untrusted users
  • Consider enforcing application sandboxing or reduced‑privilege execution so that even if code runs, its impact is limited to the sandboxed environment

Generated by OpenCVE AI on September 22, 2026 at 21:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Modeler | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-23T03:56:04.375Z

Reserved: 2026-08-27T21:20:45.366Z

Link: CVE-2026-81998

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:53.043

Modified: 2026-09-23T04:17:52.887

Link: CVE-2026-81998

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:15:07Z

Weaknesses