Junglewise Threat Intelligence

CVE-2026-48427: Adobe Substance3D Designer out-of-bounds write

CVE-2026-48427 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3d Designer, Adobe Substance3D Designer. Vendors: Adobe.

Executive brief

Adobe Substance3D Designer, a professional 3D design and texturing application, contains an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code with the privileges of the current user. An attacker must trick a user into opening a specially crafted malicious file to trigger the vulnerability, potentially compromising the designer's system and any work or credentials stored on it.

Technical details

The vulnerability is an out-of-bounds write flaw in Adobe Substance3D Designer that allows arbitrary code execution in the context of the current user. The attack vector requires user interaction, specifically the opening of a malicious file that triggers the memory corruption. No special authentication or elevated privileges are required beyond standard user execution context. The vulnerability has not been exploited in the wild as of the advisory date, though patches are expected to be available through Adobe's standard security update mechanisms.

Affected products

  • Adobe Substance3D Designer

Timeline

  • 2026-08-25: disclosed

References

Related threats