Junglewise Threat Intelligence

CVE-2026-48424: Adobe Substance3D Sampler heap buffer overflow

CVE-2026-48424 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3D Sampler, Adobe Substance3D Sampler. Vendors: Adobe.

Executive brief

Adobe Substance3D Sampler is a 3D texture and material creation tool used by designers and artists. The application contains a heap buffer overflow vulnerability that could allow an attacker to execute arbitrary code on a user's system if they open a specially crafted malicious file. Exploitation requires the user to manually open a malicious file, but successful exploitation could compromise the entire workstation.

Technical details

Substance3D Sampler is affected by a heap-based buffer overflow vulnerability that arises from improper input validation when processing malicious files. The vulnerability is triggered when a user opens a specially crafted file in the application, causing a heap buffer overflow that an attacker can leverage to achieve arbitrary code execution with the privileges of the current user. The attack requires user interaction in the form of opening a malicious file; no network-based exploitation vector is available. Adobe has identified and patched this vulnerability; users should update to the latest version of Substance3D Sampler.

Affected products

  • Adobe Substance3D Sampler

Timeline

  • 2026-08-25: disclosed

References

Related threats