Junglewise Threat Intelligence

CVE-2026-34709: Adobe Substance 3D Sampler out-of-bounds write

CVE-2026-34709 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Adobe Substance 3D Sampler. Vendors: Adobe.

Executive brief

Adobe Substance 3D Sampler, a professional tool used for creating 3D materials and environments, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized software execution, potentially compromising sensitive data or system integrity.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Substance 3D Sampler versions 6.0.0 and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code in the context of the current user. Exploitation requires local access to deliver the file and relies on user interaction (opening the malicious file). Adobe has addressed this in security bulletin APSB26-60.

Affected products

  • Adobe Substance 3D Sampler 6.0.0 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats