Junglewise Threat Intelligence

CVE-2026-48305: Adobe Substance 3D Sampler out-of-bounds write

CVE-2026-48305 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Adobe Substance 3D Sampler. Vendors: Adobe.

Executive brief

Adobe Substance 3D Sampler, a professional tool for creating 3D materials from real-world images, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized software execution, data theft, or full system compromise under the permissions of the logged-in user.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Substance 3D Sampler versions 6.0.0 and earlier. The flaw is triggered when the application improperly handles memory during the parsing of a specially crafted file. An attacker can exploit this by convincing a victim to open a malicious file, leading to memory corruption and potentially arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Adobe has addressed this in later versions, and users are advised to update to the latest available release.

Affected products

  • Adobe Substance 3D Sampler 6.0.0 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats