Junglewise Threat Intelligence

CVE-2026-48420: Adobe Substance3D Sampler out-of-bounds write

CVE-2026-48420 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3D Sampler, Adobe Substance3D Sampler. Vendors: Adobe.

Executive brief

Substance3D Sampler is a 3D texture and material creation tool used by digital artists and designers. A flaw in the software allows an attacker to execute arbitrary code on a user's system by crafting a malicious file; this requires the victim to open the file, and would give the attacker full control over the compromised machine.

Technical details

The vulnerability is an out-of-bounds write flaw in Substance3D Sampler that can be triggered by processing a specially crafted input file. The attack requires user interaction—specifically, a victim must open a malicious file—but does not require authentication or elevated privileges beforehand. Successful exploitation results in arbitrary code execution in the context of the current user. Patches are expected to be available through Adobe's security advisory APSB26-121.

Affected products

  • Adobe Substance3D Sampler <UNKNOWN>

Timeline

  • 2026-08-25: disclosed
  • advisory: APSB26-121

References

Related threats