Junglewise Threat Intelligence

CVE-2026-34675: Adobe Substance 3D Painter out-of-bounds write

CVE-2026-34675 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Adobe Substance 3d Painter. Vendors: Adobe.

Executive brief

Adobe Substance 3D Painter, a professional 3D texturing and painting application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized software execution, data theft, or complete system compromise in the context of the logged-in user.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Substance 3D Painter versions 12.0.2 and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the current user. Exploitation requires local delivery of a malicious file and user interaction (opening the file). Adobe has addressed this in version 12.0.3.

Affected products

  • Adobe Substance 3D Painter 12.0.2 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Adobe released security bulletin APSB26-55

References

Related threats