Junglewise Threat Intelligence

CVE-2026-48428: Adobe Substance3D Designer heap buffer overflow

CVE-2026-48428 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3d Designer, Adobe Substance3D Designer. Vendors: Adobe.

Executive brief

Substance3D Designer, Adobe's professional 3D content creation tool, is vulnerable to a heap-based buffer overflow that allows an attacker to execute arbitrary code with the privileges of the user running the application. An attacker must trick a user into opening a specially crafted malicious file to trigger the vulnerability, making this a practical risk for designers and artists who may receive files from untrusted sources.

Technical details

A heap-based buffer overflow vulnerability exists in Adobe Substance3D Designer, allowing arbitrary code execution in the context of the current user. The vulnerability is triggered by parsing a malicious file that the user must open—no network access or elevated privileges are required for exploitation. The attacker must craft a specific file format that, when processed by the application, causes a buffer overrun on the heap, enabling arbitrary code execution with user-level privileges. User interaction (opening a file) is required to trigger the vulnerability.

Affected products

  • Adobe Substance3D Designer

Timeline

  • 2026-08-25: disclosed

References

Related threats