Junglewise Threat Intelligence

CVE-2026-48419: Adobe Substance3D Sampler out-of-bounds write

CVE-2026-48419 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3D Sampler, Adobe Substance3D Sampler. Vendors: Adobe.

Executive brief

Adobe Substance3D Sampler is a 3D texturing and design tool used by creative professionals. A flaw in the application allows attackers to execute arbitrary code on a user's computer by tricking them into opening a malicious file. Successful exploitation could lead to complete system compromise, data theft, or malware installation.

Technical details

The vulnerability is an out-of-bounds write flaw in Substance3D Sampler that allows arbitrary code execution in the context of the current user. The attack requires user interaction—specifically, a victim must open a specially crafted malicious file to trigger the vulnerability. No network access or elevated privileges are required. An attacker who successfully exploits this issue can execute arbitrary code with the privileges of the logged-in user, potentially compromising the system and accessing sensitive project files or credentials.

Affected products

  • Adobe Substance3D Sampler

Timeline

  • 2026-08-25: disclosed

References

Related threats