Junglewise Threat Intelligence

CVE-2026-48421: Adobe Substance3D Sampler out-of-bounds write

CVE-2026-48421 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3D Sampler, Adobe Substance3D Sampler. Vendors: Adobe.

Executive brief

Adobe Substance3D Sampler is a 3D design and texture creation tool used by digital artists and designers. The application is affected by an out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code with the privileges of the user running the application. Exploitation requires a victim to open a specially crafted malicious file, making this a practical risk in design workflows where files are frequently shared and opened.

Technical details

The vulnerability is a classic out-of-bounds write flaw in memory management, occurring when the application writes data beyond the allocated bounds of a buffer. This allows an attacker to overwrite adjacent memory regions, potentially corrupting heap metadata or overwriting function pointers to achieve arbitrary code execution. The attack vector is local and user-initiated: a victim must open a malicious file in Substance3D Sampler for the vulnerability to trigger. No authentication or elevated privileges are required for exploitation beyond the user interaction of opening the file. The specific affected versions and patch availability details are not currently accessible, but Adobe has issued advisory APSB26-121.

Affected products

  • Adobe Substance3D Sampler

Timeline

  • 2026-08-25: disclosed: Publicly disclosed via NVD and Adobe advisory APSB26-121

References

Related threats