Executive brief
Adobe Substance3D Painter is a professional 3D design and texturing application used by digital artists and game developers. Versions 11.1.2 and earlier contain an out-of-bounds read vulnerability that allows attackers to access sensitive data stored in application memory by tricking users into opening a malicious file. This could expose confidential project data or credentials.
Technical details
The vulnerability is an out-of-bounds read flaw in Substance3D Painter's file parsing logic that occurs when processing specially crafted input files. The defect allows an attacker to read memory regions beyond the intended bounds of a buffer, potentially exposing sensitive information such as encryption keys, user data, or other confidential content stored in the application's memory space. Exploitation requires user interaction: a victim must be tricked into opening a malicious file. The vulnerability affects versions 11.1.2 and earlier; patch status and availability of fixes should be verified through Adobe's official security bulletin.
Affected products
- Adobe Substance3D Painter 11.1.2 and earlier
Timeline
- 2026-03-10: disclosed: CVE published on NVD
- 2026-03-10: advisory: Adobe security bulletin APSB26-25 issued