Description
Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-22
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Substance3D Modeler contains an out‑of‑bounds write flaw that allows a crafted file to corrupt memory and execute arbitrary code in the context of the user who opens it. The vulnerability permits the attacker to overwrite critical data structures or return addresses, enabling the injection of malicious payloads. Because the code runs with the user’s privileges, a successful exploitation could lead to local account compromise, data theft, or further lateral movement in an environment where the user has administrative or high‑level access.

Affected Systems

Adobe’s Substance3D Modeler is vulnerable. No specific version set is listed in the CNA data; the flaw applies to the releases of Substance3D Modeler that are patched only after the Adobe security advisory is applied. The advisory can be found on Adobe’s support site.

Risk and Exploitability

The CVSS score for the issue is 7.8, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to open a malicious file, which means the attack vector is user‑interaction based. The lack of remote network or web‑based exploitation reduces the immediate risk of widespread attacks, but users who routinely open or import files from untrusted sources remain at significant risk of arbitrary code execution.

Generated by OpenCVE AI on September 22, 2026 at 21:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the patch for Substance3D Modeler released in the Adobe security advisory to eliminate the out‑of‑bounds write flaw.
  • Disable automatic opening of unknown or untrusted files and use a file‑filtering solution to block suspicious content from entering the environment.
  • Run Substance3D Modeler in a sandboxed process or with the least‑privilege user account to contain any compromised execution surface.

Generated by OpenCVE AI on September 22, 2026 at 21:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Substance3D - Modeler | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-23T03:56:03.497Z

Reserved: 2026-09-01T00:25:45.963Z

Link: CVE-2026-83963

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:54.010

Modified: 2026-09-23T04:17:54.750

Link: CVE-2026-83963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:15:07Z

Weaknesses