Junglewise Threat Intelligence

CVE-2026-48417: Adobe Substance3D Sampler stack-based buffer overflow

CVE-2026-48417 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3D Sampler, Adobe Substance3D Sampler. Vendors: Adobe.

Executive brief

Adobe Substance3D Sampler, a 3D design and material creation tool, contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code on a user's computer. An attacker must trick a victim into opening a specially crafted malicious file, after which the attacker gains the same permissions as the logged-in user.

Technical details

A stack-based buffer overflow vulnerability exists in Adobe Substance3D Sampler due to improper input validation or bounds checking when processing malicious files. The vulnerability can be exploited by crafting a specially formatted file that, when opened by a user, triggers a buffer overflow on the stack. This allows an attacker to overwrite memory and achieve arbitrary code execution in the context of the current user. User interaction is required—the victim must open the malicious file—which limits the attack vector to social engineering. No patch information is readily available from the provided advisory data.

Affected products

  • Adobe Substance3D Sampler

Timeline

  • 2026-08-25: disclosed

References

Related threats