Description
Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-22
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow (CWE-121) in Substance3D – Modeler that can be triggered by opening a specially crafted file. This flaw allows an attacker to execute arbitrary code within the victim’s user context, compromising confidentiality, integrity, and availability of the host system.

Affected Systems

Adobe’s Substance3D – Modeler is affected. No specific version numbers were provided in the advisory, so all installations of the product that match the product name should be considered at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability. The attacker must supply and open a malicious file, so user interaction is required; it is not a remote exploitation vector. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high severity combined with the requirement for user action makes this a significant threat for environments where users may receive or handle untrusted files.

Generated by OpenCVE AI on September 22, 2026 at 21:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Adobe’s security patch for Substance3D – Modeler as detailed in the official bulletin.
  • Until the patch is available, avoid opening files from unknown or untrusted sources in Substance3D – Modeler and disable file import features if possible.
  • Monitor system logs for anomalous process creation following file imports, and keep user accounts on the principle of least privilege.

Generated by OpenCVE AI on September 22, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Modeler | Stack-based Buffer Overflow (CWE-121)
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T19:17:31.585Z

Reserved: 2026-09-01T00:25:45.963Z

Link: CVE-2026-83962

cve-icon Vulnrichment

Updated: 2026-09-22T19:17:12.644Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:53.877

Modified: 2026-09-22T20:17:09.633

Link: CVE-2026-83962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:45:06Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow