Junglewise Threat Intelligence

CVE-2026-48423: Adobe Substance3D Sampler heap buffer overflow

CVE-2026-48423 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3D Sampler, Adobe Substance3D Sampler. Vendors: Adobe.

Executive brief

Adobe Substance3D Sampler is a 3D content creation tool used by designers and artists. A heap buffer overflow vulnerability allows attackers to execute arbitrary code on a user's system if they trick the user into opening a malicious file, potentially compromising creative projects, intellectual property, and the underlying workstation.

Technical details

This vulnerability is a heap-based buffer overflow in Adobe Substance3D Sampler that can be triggered by processing a specially crafted file. The issue allows an attacker to overflow a heap buffer, potentially overwriting adjacent memory structures and achieving arbitrary code execution within the context of the logged-in user. Exploitation requires user interaction—a victim must be tricked into opening a malicious file. No public exploits have been reported in the wild as of the advisory date. Patches are expected to be available through Adobe security updates.

Affected products

  • Adobe Substance3D Sampler

Timeline

  • 2026-08-25: disclosed

References

Related threats