Junglewise Threat Intelligence

CVE-2026-34674: Adobe Substance3D Sampler heap buffer overflow

CVE-2026-34674 · Severity: high · CVSS 7.8 · Published 2026-08-27

Technologies: Adobe Substance 3d Painter, Adobe Substance3D Sampler. Vendors: Adobe.

Executive brief

Adobe Substance3D Sampler is a 3D material creation tool used by designers and artists. A heap buffer overflow vulnerability in versions 5.1.3 and earlier could allow an attacker to execute arbitrary code on a user's system if they open a malicious file, potentially compromising the user's account and data.

Technical details

A heap-based buffer overflow exists in Adobe Substance3D Sampler versions 5.1.3 and earlier. The vulnerability is triggered when the application processes a specially crafted input file, allowing an attacker to overflow a heap buffer and overwrite adjacent memory. Exploitation requires user interaction—the victim must open a malicious file. Successful exploitation results in arbitrary code execution in the context of the current user. No information on patch availability is provided in the advisory.

Affected products

  • Adobe Substance3D Sampler 5.1.3 and earlier

Timeline

  • 2026-08-27: disclosed

References

Related threats